HUMAN VERIFICATION REQUIREDASVS 4.2.3 HTTP/2 and HTTP/3 header restrictions
MB-C18ASVS Level 3 Human AssuranceHigh
The application does not send nor accept HTTP/2 or HTTP/3 messages with connection-specific header fields such as Transfer-Encoding to prevent response splitting and header injection attacks.