Kavach

Check · Operational hygiene · default severity medium

Software version disclosure

What Kavach checks

Whether your server advertises its exact software and version.

Why it matters

Telling the world 'nginx 1.18.0 / PHP 7.4' lets an attacker look up known exploits for that exact version in seconds.

How an attacker uses it

  1. Attacker runs one request and reads 'Server: nginx 1.18.0'.
  2. They search a CVE database for exploits against that exact version.
  3. They find a known, unpatched hole and a ready-made exploit.

How to fix it

Suppress or genericise the Server header and remove X-Powered-By at the web-server/framework level.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously