Definition · Known Vulnerabilities (CVEs)

What is Server Header Disclosure?

Most web servers and application frameworks identify themselves in their responses by default. A Server: Apache/2.4.49 (Ubuntu) header names the product, the exact version and the distribution; X-Powered-By: PHP/7.4.3 adds the runtime. None of that is needed by the client, and all of it is useful to someone deciding what to attack.

Commonly leaked headers include:

Server: nginx/1.18.0
X-Powered-By: Express
X-AspNet-Version: 4.0.30319
X-Generator: Drupal 9 (https://www.drupal.org)
X-Runtime, X-Drupal-Cache, X-Shopify-Stage, ...

Error pages, default landing pages, cookie names, ETag formats and HTTP redirect wording disclose much the same information even when the headers are removed.

Why it matters, in proportion

Version disclosure is not itself a vulnerability — removing it does not patch anything, and an attacker can often infer the software from behaviour anyway. What it does is make targeting cheap. Instead of probing broadly, an attacker matches the disclosed version against CVE records and the KEV catalogue, picks a proof-of-concept exploit known to work on that exact build, and attempts it once. At internet scale, that is the difference between a host being found by opportunistic scanning and being skipped.

The more useful way to read a version banner is as a maintenance indicator. A server announcing a release that is several years old is telling you that its patch management has lapsed, and that is a finding regardless of whether a specific exploit is available.

Suppressing it

  • Apache: ServerTokens Prod and ServerSignature Off
  • nginx: server_tokens off (removing the header entirely requires a module or a proxy)
  • IIS: remove the Server and X-AspNet-Version headers, and the X-Powered-By custom header
  • Application frameworks: disable the framework’s own identifying header, such as Express’s x-powered-by
  • Strip or rewrite headers at the CDN or reverse proxy, which catches origins you cannot easily reconfigure
  • Replace verbose error pages with generic ones, since stack traces disclose far more than a version string

Treat this as tidiness and attack surface reduction rather than a security control in its own right — obscuring the version buys time, patching removes the problem. SurfaceLoop reads response headers and service banners across an estate for exactly this reason, using disclosed versions as the basis for external CVE detection.

See banner grabbing, service fingerprinting, CPE, security misconfiguration, directory listing and known vulnerabilities.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.