# Validating Incoming Http requests

**URL:** <https://discuss.elastic.co/t/validating-incoming-http-requests/380287>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 21, 2025, 6:45am UTC](https://discuss.elastic.co/t/validating-incoming-http-requests/380287 "2025-07-21T06:45:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![amjad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amjad/32/140039_2.png) [@amjad](https://discuss.elastic.co/u/amjad)\
**Post date:** [July 21, 2025, 6:45am UTC](https://discuss.elastic.co/t/validating-incoming-http-requests/380287/1 "2025-07-21T06:45:44Z")

</div>

Hi Elastic community,

Hope everyone is doing well, and thank you for your support so far.

We’ve encountered a vulnerability related to incoming HTTP requests. We're currently using cURL APIs to create users in Elasticsearch. The host we're using is `elksip.til.com:9200`, which points to a load balancer hosted on Azure.

During a recent VAPT (Vulnerability Assessment and Penetration Testing), our security team used Burp Suite for testing. They found that even when the `Host` header was modified to a malicious domain like `www.hackers.com`, the request was still processed successfully and the user was created — without any errors.

We would like to restrict access so that only requests with the correct `Host` header (i.e., `elksip.til.com:9200`) are allowed.

**How can we enforce this validation in Elasticsearch 7.11?** Is there any recommended way to ensure only requests with the expected Host header are processed?

Looking forward to your guidance.

Thanks!

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 21, 2025, 8:08am UTC](https://discuss.elastic.co/t/validating-incoming-http-requests/380287/2 "2025-07-21T08:08:57Z")

</div>

> [@amjad](#):
>
> How can we enforce this validation in Elasticsearch 7.11?

Elasticsearch 7.11 went EOL almost 3 years ago long. If you are concerned about security or other bugs, you must use only supported and maintained versions. You need to upgrade to a supported version as a matter of urgency.

> [@amjad](#):
>
> We would like to restrict access so that only requests with the correct `Host` header (i.e., `elksip.til.com:9200`) are allowed.

The `Host` header is only relevant to services that implement virtual hosting, which does not include Elasticsearch, so it is deliberate that Elasticsearch ignores this header.
