← All headersResponse header

What is a Server header?

Identifies the software (and sometimes version) handling the request on the origin server.

Server identifies the software - and sometimes the exact version - handling requests on a website's origin, which is convenient for debugging but also a genuine, commonly cited security consideration, since broadcasting an exact server version makes it trivially easy for an attacker to check it against known vulnerabilities. Many security-conscious sites deliberately suppress or generalise this header rather than removing it, since a missing header is itself a minor signal.

Common use case

A security audit flags a Server header revealing an exact, outdated web server version, since an attacker can trivially cross-reference it against a public database of known vulnerabilities for that version.

Example

Server: nginx/1.25.3

History

Part of the original HTTP/1.0 specification, RFC 1945 (1996).

Did you know?

Many production deployments deliberately strip or genericise this header (e.g. down to just "nginx" with no version) as a small, low-cost piece of security hardening.