Forum Discussion

Apr 12, 2023

Does AWS Managed Ruled support HTTP header injection?

If an HTTP header with a newline code inserted is sent, can AWS Managed Rule detect and prevent it?

If so, which AWS Managed Rules are included?

  • Hi Kazuto,

    The F5 Rules for AWS WAF - Web exploits OWASP Rules has rules for blocking different HTTP Header Injections. Depending on the HTTP request and how AWS parses and handles it for inspection, the rules in place should block injections in HTTP headers. If you find that something is not blocked as expected, please share with us a sample request and we will check into it further