Invalid Header Forwarding Enabled
Application Load Balancers not configured to drop invalid HTTP headers, allowing non-RFC-compliant headers to be forwarded to backend services. This creates opportunities for header injection attacks and security control bypasses.