Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-21349

Deprecate require-host-http11 and ignore its setting

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • 39.0.0.Final
    • None
    • Web (Undertow)
    • None

      The CVE-2025-12543 fix requires the existence of a Host header when HTTP 1.1 is used, so setting the require-host-http11 attribute to false can no longer be supported. So deprecate the attribute and ignore its setting, except to log a WARN if it is explicitly set to false. (The default is false but we won't warn if the default is used.)

              bstansbe@redhat.com Brian Stansberry
              bstansbe@redhat.com Brian Stansberry
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: