Skip to content

H3-2026-0078

Insecure HTTP Connection

Category SECURITY_MISCONFIGURATION
Base Score 0.1

Description

The web application is reachable over cleartext HTTP. Either the application serves content directly over HTTP, or an HTTP request is not redirected to HTTPS with a proper secure redirect.

Impact

Traffic sent over HTTP is not encrypted. An attacker on the network path can read or modify requests and responses, which exposes session cookies, credentials, and other sensitive data. Without a secure redirect to HTTPS, a client can be downgraded to the cleartext channel.

References