HTTP/2 301
date: Fri, 26 Dec 2025 02:41:12 GMT
content-type: text/html
location: https://owasp.org/
server: cloudflare
x-github-request-id: C765:328FD3:4BBED7:54480C:694DEDCA
accept-ranges: bytes
via: 1.1 varnish
age: 2045
x-served-by: cache-bom-vanm7210076-BOM
x-cache: HIT
x-cache-hits: 1
x-timer: S1766716873.791615,VS0,VE1
vary: Accept-Encoding
x-fastly-request-id: fe650bb3b78ec35f8454aebc708cac8b75b175c0
cf-cache-status: DYNAMIC
cf-ray: 9b3d37c668540bc9-BLR
HTTP/2 200
date: Fri, 26 Dec 2025 02:41:12 GMT
content-type: text/html; charset=utf-8
cf-ray: 9b3d37c70998999b-BLR
cf-cache-status: DYNAMIC
access-control-allow-origin: *
age: 355
cache-control: max-age=600
expires: Fri, 26 Dec 2025 00:49:23 GMT
last-modified: Thu, 25 Dec 2025 05:16:55 GMT
server: cloudflare
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
via: 1.1 varnish
content-security-policy: default-src 'self' https://*.fontawesome.com https://api.github.com https://*.githubusercontent.com https://*.google-analytics.com https://owaspadmin.azurewebsites.net https://*.twimg.com https://platform.twitter.com https://www.youtube.com https://*.doubleclick.net; frame-ancestors 'self'; frame-src https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.sched.com https://*.google.com https://*.twitter.com https://www.youtube.com https://w.soundcloud.com https://buttons.github.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://viewer.diagrams.net https://fonts.googleapis.com https://*.fontawesome.com https://app.diagrams.net https://cdnjs.cloudflare.com https://cse.google.com https://*.vuejs.org https://*.stripe.com https://*.wufoo.com https://*.youtube.com https://*.meetup.com https://*.sched.com https://*.google-analytics.com https://unpkg.com https://buttons.github.io https://www.google.com https://*.gstatic.com https://*.twitter.com https://*.twimg.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.gstatic.com https://cdnjs.cloudflare.com https://www.google.com https://fonts.googleapis.com https://platform.twitter.com https://*.twimg.com data:; font-src 'self' https://*.fontawesome.com fonts.gstatic.com; manifest-src 'self' https://pay.google.com; img-src 'self' https://*.globalappsec.org https://render.com https://*.render.com https://okteto.com https://*.okteto.com data: www.w3.org https://*.bestpractices.dev https://licensebuttons.net https://img.shields.io https://*.twitter.com https://github.githubassets.com https://*.twimg.com https://platform.twitter.com https://*.githubusercontent.com https://*.vercel.app https://*.cloudfront.net https://*.coreinfrastructure.org https://*.securityknowledgeframework.org https://badges.gitter.im https://travis-ci.org https://api.travis-ci.org https://s3.amazonaws.com https://snyk.io https://coveralls.io https://requires.io https://github.com https://*.googleapis.com https://*.google.com https://*.gstatic.com https://static.scarf.sh
permissions-policy: geolocation=(self)
referrer-policy: same-origin
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-cache: HIT
x-cache-hits: 0
x-fastly-request-id: 182c2a41e43dcb61a4fbec6e8ef9082dab803f38
x-github-request-id: B832:328FD3:4B1E82:5381B8:694DDA0F
x-origin-cache: HIT
x-proxy-cache: HIT
x-served-by: cache-bom-vanm7210049-BOM
x-timer: S1766716873.857761,VS0,VE1
content-encoding: gzip
OWASP Foundation, the Open Source Foundation for Application Security | OWASP Foundation
For full functionality of this site it is necessary to enable JavaScript. Here are the instructions how to enable JavaScript in your web browser .
Are you an OWASP Member?
The 2025 Elections are around the corner! Do you want a say in how OWASP is run? Please join or renew your membership today!
More details
Andrew van der Stock , November 19, 2025
The OWASP Foundation is pleased to announce the appointment of Stacey Ebbs as Communications and Marketing Manager. Stacey brings more than a decade of experience in marketing, events, and community engagement within the cybersecurity and technology sectors.
...read more
Quick access to our highlighted
flagship resources
Documentation
Top Ten
The reference standard for the most critical web application security risks
Documentation
ASVS
Application security verification standard
Documentation
Cheat Sheets
List of crucial app security information
Have an idea for a project?
Take advantage of our resources and let it grow with OWASP.
Recent OWASP News & Opinions
Upcoming Conferences
OWASP Global AppSec EU 2026 - Vienna, Austria , June 22-26, 2026
OWASP Global AppSec USA 2026 - San Francisco, CA , November 2-6, 2026
OWASP Global AppSec EU 2027 - Vienna, Austria , June 21-25, 2027
OWASP Global AppSec USA 2027 - Atlanta, GA , September 20-24, 2027