HSTS Missing From HTTPS Server

priboyano

New Member
Sep 2, 2026
1
0
1
Hello,

We have identified the following vulnerability on our Proxmox VE web interface:

HSTS Missing From HTTPS Server (RFC 6797)

Is there an officially supported way to configure the Strict-Transport-Security (HSTS) HTTP header directly in pveproxy?

We could not find a documented native configuration option for this.

If there is no supported way to configure it, is using a reverse proxy the recommended approach?

Also, if we manually modify pveproxy or its underlying configuration to add the HSTS header, would this be considered a supported configuration and would the changes be preserved after updates?

We need this information to address the finding and provide evidence to our Compliance team.

Thank you!
 
  • Like
Reactions: priboyano