HTTP QUERY Method: New Verb Blurs GET/POST Boundaries
What Happened — In June 2026 the IETF released RFC 10008, introducing a new HTTP verb called QUERY. It is positioned between the safe, cache‑friendly GET and the body‑carrying POST, allowing clients to send a request body while retaining query‑style semantics.
Why It Matters for Trust & Control Assurance
- The QUERY verb creates a gray‑area for existing API security controls (e.g., input validation, method‑based firewall rules). Continuous control‑assurance programs must surface this new vector and capture evidence that it is governed.
- Logging and audit trails that currently filter on GET/POST may miss QUERY traffic, weakening the defensible evidence needed for audits.
- Mapping QUERY to a control objective (e.g., “ensure all inbound request methods are authorized and monitored”) satisfies multiple frameworks simultaneously.
Who Is Affected — SaaS platforms, cloud‑native APIs, web‑application firewalls, and any organization that exposes HTTP endpoints.
Recommended Actions
- Update API gateway and WAF policies to explicitly allow or block the QUERY method.
- Extend logging schemas to record QUERY requests and associated payloads.
- Incorporate QUERY into your continuous control‑mapping process and map the control to the relevant VCF objective (method authorization and monitoring).
Technical Notes — No CVE is associated; the change is a protocol evolution. Potential misuse arises if developers treat QUERY like GET (ignoring the body) or like POST (bypassing existing method‑based controls). Source: SANS Internet Storm Center