* x_xss_protection * strict_transport_security (HSTS) * x_content_type_options these are currently defaulted to false (off) until the next minor release. fixes #17509 (cherry picked from commit 599514ad68)
599514ad68