This header has been deprecated by modern browsers and its use can introduce additional security issues on the client side. See https://owasp.org/www-project-secure-headers/#x-xss-protection
Comment From: jzheaux
This seems related to https://github.com/spring-projects/spring-security/issues/9631.
Comment From: marcusdacoregio
Closing as duplicate of #9631