Response header name interning does not have same-origin protections and are stored in a global registry. This allows stored header names to be available cross-origin. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7797 Acknowledgements: Name: the Mozilla project Upstream: Anne van Kesteren