This header has been deprecated by modern browsers and its use can introduce additional security issues on the client side. See https://owasp.org/www-project-secure-headers/#x-xss-protection

Comment From: jzheaux

This seems related to https://github.com/spring-projects/spring-security/issues/9631.

Comment From: marcusdacoregio

Closing as duplicate of #9631