: How to disable http method verb tunneling in nginx Our security team ran a web-inspect security scan on our site and asked us to disable verb tunneling using headers or query parameters such
Our security team ran a web-inspect security scan on our site and asked us to disable verb tunneling using headers or query parameters such as X-HTTP-Method, XHTTP-Method-Override, X-Method-Override, or a query parameter such as _method to prevent attackers from using an override method to use restricted HTTP methods. Is there a way in nginx configurations where we can disable this verb tunneling ?
More posts by @Welton855
Terms of Use Create Support ticket Your support tickets Stock Market News! © vmapp.org2025 All Rights reserved.