---
title: "Deprecation: #95395 - GeneralUtility::isAllowedHostHeaderValue() and TRUSTED_HOSTS_PATTERN constants"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:deprecation-95395"
source: "Changelog/11.5/Deprecation-95395-GeneralUtilityIsAllowedHostHeaderValueAndTrustedHostsPatternConstants.rst"
typo3-version: "11.5"
typo3-major: 11
type: "deprecation"
issue: 95395
forge: "https://forge.typo3.org/issues/95395"
tags: ["PHP-API", "FullyScanned", "ext:core"]
rendered: "2026-10-03T08:19:36+00:00"
---

# Deprecation: #95395 - GeneralUtility::isAllowedHostHeaderValue() and TRUSTED_HOSTS_PATTERN constants {#deprecation-95395}

See [forge#95395](https://forge.typo3.org/issues/95395)

## Description {#description}

The PHP method
`\TYPO3\CMS\Core\Utility\GeneralUtility::isAllowedHostHeaderValue()`
and the PHP constants
`\TYPO3\CMS\Core\Utility\GeneralUtility::ENV_TRUSTED_HOSTS_PATTERN_ALLOW_ALL`
and
`\TYPO3\CMS\Core\Utility\GeneralUtility::ENV_TRUSTED_HOSTS_PATTERN_SERVER_NAME`
have been deprecated.

## Impact {#impact}

A deprecation will be logged in TYPO3 v11 if
`\TYPO3\CMS\Core\Utility\GeneralUtility::isAllowedHostHeaderValue()` is
used. It is unlikely for extensions to have used this as the host header
is checked for every frontend and backend request anyway.

Usage of the constants will cause a PHP error "Undefined class constant" in
TYPO3 v12, the method
`\TYPO3\CMS\Core\Utility\GeneralUtility::isAllowedHostHeaderValue()` will be
dropped without replacement.

## Affected Installations {#affected-installations}

Installations using the constants instead of static strings or
that call the method explicitly – which is unlikely.

## Migration {#migration}

Use `'.*'` instead of
`\TYPO3\CMS\Core\Utility\GeneralUtility::ENV_TRUSTED_HOSTS_PATTERN_ALLOW_ALL`
and `'SERVER_NAME'` instead of
`\TYPO3\CMS\Core\Utility\GeneralUtility::ENV_TRUSTED_HOSTS_PATTERN_SERVER_NAME`.

Don't use  `\TYPO3\CMS\Core\Utility\GeneralUtility::isAllowedHostHeaderValue()`.
