Skip to content

[BUG] Server-Timing header being reported as Server Banner #2787

Closed
@gooseleggs

Description

@gooseleggs

I am running version: testssl.sh version 3.2.0 from https://testssl.sh/ (just pulled latest version)

Command line / docker command to reproduce

testssl.sh glueware.co.nz

Expected behavior

I would expect the Server-Banner response to be empty as this is not being returned by the website. However, the Server Banner is displaying the Server-Timing header results.

Server banner Server-Timing: cache;desc=hit, varnish;desc=hit, dc;desc=blahblah

Your system (please complete the following information):

  • OS: Kali GNU/Linux Rolling
  • Platform: Linux 6.12.20-amd64 x86_64
  • OpenSSL + bash:
  Using OpenSSL 1.0.2-bad (Mar 28 2025)  [~183 ciphers]
  Using bash 5.2.37

Additional context

Not sure that there is anything else to add.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions