Home › Intelligence › Brief
BREACH BRIEF⚪ Informational Advisory

IETF Publishes RFC 10008 Adding HTTP QUERY Method Between GET and POST

The IETF released RFC 10008, defining a new HTTP verb called QUERY that blends GET‑style semantics with a request body. Organizations must update their control‑assurance programs to authorize, log, and monitor this method to maintain audit readiness.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 isc.sans.edu
⚪
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
isc.sans.edu

HTTP QUERY Method: New Verb Blurs GET/POST Boundaries

What Happened — In June 2026 the IETF released RFC 10008, introducing a new HTTP verb called QUERY. It is positioned between the safe, cache‑friendly GET and the body‑carrying POST, allowing clients to send a request body while retaining query‑style semantics.

Why It Matters for Trust & Control Assurance

  • The QUERY verb creates a gray‑area for existing API security controls (e.g., input validation, method‑based firewall rules). Continuous control‑assurance programs must surface this new vector and capture evidence that it is governed.
  • Logging and audit trails that currently filter on GET/POST may miss QUERY traffic, weakening the defensible evidence needed for audits.
  • Mapping QUERY to a control objective (e.g., “ensure all inbound request methods are authorized and monitored”) satisfies multiple frameworks simultaneously.

Who Is Affected — SaaS platforms, cloud‑native APIs, web‑application firewalls, and any organization that exposes HTTP endpoints.

Recommended Actions

  • Update API gateway and WAF policies to explicitly allow or block the QUERY method.
  • Extend logging schemas to record QUERY requests and associated payloads.
  • Incorporate QUERY into your continuous control‑mapping process and map the control to the relevant VCF objective (method authorization and monitoring).

Technical Notes — No CVE is associated; the change is a protocol evolution. Potential misuse arises if developers treat QUERY like GET (ignoring the body) or like POST (bypassing existing method‑based controls). Source: SANS Internet Storm Center

📰 Original Source
https://isc.sans.edu/diary/rss/33352 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →