Forum Discussion
Emil_T
Cirrus
Aug 11, 2024Leading tab in header name: Authorization
I have a violation / suggestion a detection of Leading tab in header named: "Authorization" When I look at the request, I don't see the "TAB" in the header name. I expect to see something like this:...
Emil_Tr
Altocumulus
Mar 03, 2025The rule of the signature is seeking a horizontal tab after the line feed which only happens in the header name. But, this version is affected by ID1003765 which detects the pattern in the base64 value even if it's disabled. The issue is fixed in version 16.1.4:
Bug ID 1003765: Authorization header signature triggered even when explicitly disabled
https://cdn.f5.com/product/bugtracker/ID1003765.html
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
