In June 2026, the IETF published RFC 10008 defining a new HTTP method called QUERY, which combines properties of GET and POST by allowing a request body while remaining safe and idempotent. Security infrastructure built before QUERY's introduction—including WAFs, API gateways, and caches—often lacks rules for this method, creating potential bypasses for SQL injection, XSS, and cache poisoning attacks, though behavioral C2 detection remains largely unaffected.