Check · Browser protection · default severity low
MIME-sniffing protection
What Kavach checks
Stops browsers from guessing a file's type and running an upload as script.
Why it matters
Blocks attacks where a user-uploaded 'image' is sniffed and executed as JavaScript.
How an attacker uses it
- Attacker uploads a file that is really JavaScript, named like an image.
- Without nosniff, the browser guesses its type and executes it.
How to fix it
Add: X-Content-Type-Options: nosniff
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.