HTTP 425 Keeps Replay-Sensitive Requests Out of TLS Early Data
TLS 1.3 can carry application data before a resumed handshake completes, which means an HTTP request can reach server processing earlier than the connection has its final handshake state. That latency optimization changes a security property: early data can be replayed, so a request that is safe to execute once can become unsafe when the same bytes are accepted more than once. HTTP status 425 Too Early marks the boundary between transport acceptance and application acceptance. A server can accept TLS early data at the connection layer yet decline to process a particular HTTP request from that data. The client can then retry after the handshake completes, where the early-data replay condition no longer applies.