Fix

X-Content-Type-Options

Prevents MIME-sniffing by forcing the browser to respect the declared Content-Type.

InfoCategory: headers
Recommended fix
Set header
X-Content-Type-Options: nosniff