STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must interpret and normalize ambiguous HTTP requests or terminate the TCP connection.

DISA Rule

SV-264364r984437_rule

Vulnerability Number

V-264364

Group Title

SRG-APP-000251

Rule Version

SRG-APP-000251-WSR-000194

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to interpret HTTP headers so they are normalized and unambiguous. The web server must validate requests that report message body as "zero" in the HTTP header.

Configure the web server to drop ambiguous requests that cannot be normalized and terminate the TCP connection.

Check Contents

Verify the web server normalizes ambiguous requests or terminates the TCP connection.

If the web server does not drop ambiguous requests that cannot be normalized and terminate the TCP connection, this is a finding.

Vulnerability Number

V-264364

Documentable

False

Rule Version

SRG-APP-000251-WSR-000194

Severity Override Guidance

Verify the web server normalizes ambiguous requests or terminates the TCP connection.

If the web server does not drop ambiguous requests that cannot be normalized and terminate the TCP connection, this is a finding.

Check Content Reference

M

Target Key

2910