STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must terminate the connection if server-level exceptions are triggered when handling requests to prevent HTTP request smuggling attacks.

DISA Rule

SV-264365r984440_rule

Vulnerability Number

V-264365

Group Title

SRG-APP-000251

Rule Version

SRG-APP-000251-WSR-000195

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure web server to terminate the connection if server-level exceptions are triggered when handling requests to prevent HTTP request smuggling attacks.

Check Contents

Verify the web server terminates the connection if server-level exceptions are triggered when handling requests.

If the web server does not terminate the connection if server-level exceptions are triggered when handling requests, this is a finding.

Vulnerability Number

V-264365

Documentable

False

Rule Version

SRG-APP-000251-WSR-000195

Severity Override Guidance

Verify the web server terminates the connection if server-level exceptions are triggered when handling requests.

If the web server does not terminate the connection if server-level exceptions are triggered when handling requests, this is a finding.

Check Content Reference

M

Target Key

2910