HUMAN VERIFICATION REQUIREDASVS 4.2.4 Reject CR/LF in modern HTTP headers
MB-C18ASVS Level 3 Human AssuranceHigh
The application only accepts HTTP/2 and HTTP/3 requests where the header fields and values do not contain any CR (\\r), LF (\\n), or CRLF (\\r\\n) sequences, to prevent header injection attacks.