A standard HTTP 406 response means the server examined the client’s preferences—such as media type, language or encoding—and could not select a matching representation it was willing to send. It is not a generic permissions error, and blindly disabling security software is not a diagnosis.

What 406 means in HTTP

RFC 9110 defines 406 Not Acceptable as the response for a resource that has no current representation acceptable under the request’s proactive content-negotiation headers, when the server is also unwilling to supply a default representation. The server should, where practical, tell the client what alternatives are available. RFC 9110, section 15.5.7

A representation is one form of the resource: JSON rather than HTML, French rather than English, or one supported compression method rather than another. The URL can be valid while the requested form is not.

The headers that matter

The request most often expresses preferences through:

  • Accept, for media types such as text/html or application/json.
  • Accept-Language, for preferred human languages.
  • Accept-Encoding, for compression formats such as gzip or br.

A server may choose among variants, return a default or reject the request. MDN notes that returning a useful 200 response with a default representation can be preferable to 406 in some implementations, but the correct behaviour depends on the API or site contract. MDN 406 reference

If you are visiting a website

Retry the exact URL in a normal, up-to-date browser. If it works in a private window, compare extensions and custom privacy or language settings; they may be altering request headers. If only one link fails, changing your entire browser configuration is unlikely to be the right fix.

When reporting the problem, include the URL, approximate time, browser, whether you were signed in and a screenshot of the response. Do not send passwords, cookies or authentication tokens. A site operator needs enough context to find the matching server log entry.

If you run the site or API

Reproduce before changing anything. Capture the raw request and response with browser developer tools or a command-line client, then vary one header at a time:

  • Request the resource without custom headers and record the status, Content-Type and Vary response header.
  • Try the exact media type your application expects, such as Accept: application/json.
  • Compare language and encoding preferences with the variants the server can actually produce.
  • Inspect application, reverse-proxy and web-server logs for the same timestamp and request ID.
  • If a firewall or ModSecurity rule intercepted the request, identify the rule ID and triggering input before tuning or excluding it.

For example, compare `curl -i https://example.com/resource` with `curl -i -H "Accept: application/json" https://example.com/resource`. A difference isolates negotiation; it does not yet tell you whether the client requested the wrong type or the server failed to expose a supported one.

Why security software sometimes appears in a 406 investigation

Some web-application firewall deployments use 406 as their blocking response even though the underlying event is not content negotiation. The OWASP ModSecurity Core Rule Set can also produce false positives that need rule-specific tuning. A 406 status alone therefore does not prove that a firewall caused the problem. OWASP ModSecurity Core Rule Set

Check the security audit log for a matching rule ID. If the request is legitimate, narrow the exception to the affected parameter or route and document it. Disabling the whole firewall, a plugin or all rules may hide the symptom while creating a larger security problem.

Do not confuse 406 with neighbouring errors

A 415 Unsupported Media Type normally concerns the format of the request body the client sent. A 403 Forbidden means the server understood the request but refuses to authorise it. A 404 means it did not find the target resource. A 406 concerns the response representation—or a non-standard component that has chosen to reuse that status.

The useful question is not “which cache should I clear?” It is “which component returned this status, and what evidence explains its decision?” Once the failing layer is known, the fix is usually small: correct a client header, add or configure a server variant, provide a sensible default, or tune one documented security rule.

Sources