← Back to Baseline

MB-R297

HUMAN VERIFICATION REQUIRED ASVS 4.2.4 Reject CR/LF in modern HTTP headers

MB-C18 ASVS Level 3 Human Assurance High

The application only accepts HTTP/2 and HTTP/3 requests where the header fields and values do not contain any CR (\\r), LF (\\n), or CRLF (\\r\\n) sequences, to prevent header injection attacks.