← Back to Baseline

MB-R296

HUMAN VERIFICATION REQUIRED ASVS 4.2.3 HTTP/2 and HTTP/3 header restrictions

MB-C18 ASVS Level 3 Human Assurance High

The application does not send nor accept HTTP/2 or HTTP/3 messages with connection-specific header fields such as Transfer-Encoding to prevent response splitting and header injection attacks.