AWS ALB does not drop invalid headers

Configure AWS ALBs to remove HTTP headers with invalid names.

Description

The ALB drop_invalid_header_fields setting removes HTTP headers whose names contain characters the ALB does not permit. If forwarded to the backend, these headers may be interpreted differently by different components.

Potential impact

Abnormal headers can reach the application and cause request-processing errors or inconsistent interpretation.

Remediation

Set drop_invalid_header_fields = true and check that required custom headers still reach the application. If you use a module, check its corresponding input.

Examples

The examples configure the ALB to remove headers with invalid names.

Before

hcl
resource "aws_lb" "disabled_1" {
  internal           = false
  load_balancer_type = "application"
  name               = "alb"
  subnets            = module.vpc.public_subnets
}

After

hcl
resource "aws_lb" "enabled" {
  internal                   = false
  load_balancer_type         = "application"
  name                       = "alb"
  subnets                    = module.vpc.public_subnets
  drop_invalid_header_fields = true
}

References