Check · Operational hygiene · default severity medium
Software version disclosure
What Kavach checks
Whether your server advertises its exact software and version.
Why it matters
Telling the world 'nginx 1.18.0 / PHP 7.4' lets an attacker look up known exploits for that exact version in seconds.
How an attacker uses it
- Attacker runs one request and reads 'Server: nginx 1.18.0'.
- They search a CVE database for exploits against that exact version.
- They find a known, unpatched hole and a ready-made exploit.
How to fix it
Suppress or genericise the Server header and remove X-Powered-By at the web-server/framework level.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.