Security Considerations for Optimistic Protocol Transitions in HTTP/1.1
RFC 9931, “Security Considerations for Optimistic Protocol Transitions in HTTP/1.1”, is a Proposed Standard document published in March 2026 by B. Schwartz. It updates RFC 9112, RFC 9298. The canonical text is published by the RFC Editor.
Abstract
In HTTP/1.1, the client can request a change to a new protocol on the existing connection. This document discusses the security considerations that apply to data sent by the client before this request is confirmed and adds new requirements to RFCs 9112 and 9298 to avoid related security issues.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9931 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9930 Tunnel Extensible Authentication Protocol Version 1
- RFC 9932 Mutually Authenticating TLS in the Context of Federations
- RFC 9929 IGP Unreachable Prefix Announcement
- RFC 9928 DHCPv4 over DHCPv6 with Relay Agent Support
- RFC 9934 Privacy-Enhanced Mail File Format for Encrypted ClientHello
- RFC 9927 Fixing the C-Flag in the Extended Address Registration Option
- RFC 9935 Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism
- RFC 9926 Prefix Registration for IPv6 Neighbor Discovery