Description
The ALB drop_invalid_header_fields setting removes HTTP headers whose names contain characters the ALB does not permit. If forwarded to the backend, these headers may be interpreted differently by different components.
Potential impact
Abnormal headers can reach the application and cause request-processing errors or inconsistent interpretation.
Remediation
Set drop_invalid_header_fields = true and check that required custom headers still reach the application. If you use a module, check its corresponding input.
Examples
The examples configure the ALB to remove headers with invalid names.
Before
hcl
resource "aws_lb" "disabled_1" {
internal = false
load_balancer_type = "application"
name = "alb"
subnets = module.vpc.public_subnets
}
After
hcl
resource "aws_lb" "enabled" {
internal = false
load_balancer_type = "application"
name = "alb"
subnets = module.vpc.public_subnets
drop_invalid_header_fields = true
}