Server response header discloses backend/edge software
mcp-tmpl-server-header-fingerprint ASI09 Human-Agent Trust Exploitation severity: info
What it detects
Server header (excluding known CDN/edge tokens) or any X-Powered-By header identifying backend/origin software. ASI09. Go probe despite the tmpl in its ID — the name predates the JSON template format.
Flags a Server header (excluding known CDN/edge tokens: cloudflare, envoy, nginx, cloudfront, varnish, akamai, fastly) or any X-Powered-By header identifying backend/origin software. Go probe despite the tmpl in its ID (name predates the later template format).
applies to MCP endpoints
Example finding
INFO mcp-tmpl-server-header-fingerprint MEDIUM CONFIDENCE Server response header discloses backend/edge software The response includes a Server or X-Powered-By header identifying backend software that appears to be the origin application, not a CDN/edge layer (which is already surfaced separately in the target fingerprint's Edge line). Not a vulnerability by itself, but useful fingerprinting context worth trimming in production. Evidence POST /mcp → 200
from a scan of reap-range, bad target
Fix
Suppress or genericize identifying response headers in production deployments where they name the origin application.
On reap-range
| insecure target | bad/mcp (Server: Werkzeug/3.0 Python/3.12.3) · Info |
| correct target | good/mcp sends no Server header |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-tmpl-server-header-fingerprint
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.