Content-Security-Policy hearder not taken into consideration in IIS 10

12 views
Skip to first unread message

Salam Elias

unread,
Nov 12, 2025, 1:00:40 PM (6 days ago) Nov 12
to ZAP User Group
I have setup the header 
Content-Security-Policy = default-src 'self'; img-src 'self' mysite.fr

When I run "Attack" I still get
The Content Security Policy fails to define one of the directives that has no fallback. Missing/excluding them is the same as allowing anything.

I am new to this tool, what does this mean and how it can be fixed? Thanks

kingthorin+zap

unread,
Nov 14, 2025, 9:55:08 AM (4 days ago) Nov 14
to ZAP User Group
You should generate a report that has a full details of the alert.

Anyway the issue is that while you have a CSP there are some directive that don't fall back to default-src so if you haven't defined them, that's the same as defining them as wildcard.

Reply all
Reply to author
Forward
0 new messages