Topic163 problems

Reverse Proxy Security

163 incident problems about Reverse Proxy Security. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (163)

SECURITY-1192Auth hardening breaks API clientsA public hardening checklist changed proxy header behavior. Browser auth appears fine, but downstream API flows now break because the app no longer sees the scheme and host headers it expects.SecurityIntermediate18 minProSECURITY-1381A Cloudflare mTLS policy protects the main API and one versioned path stays...A Cloudflare mTLS policy protects the main API and one versioned path stays... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge auth failures often come from precedence between broad exceptions a...SecurityAdvanced14 minProSECURITY-1376A fail2ban-style parser sees every request as the CDN edgeA proxy trust configuration is updated and later automated bans begin hitting CDN edges or harmless intermediaries instead of abusive clients.SecurityAdvanced14 minProSECURITY-1345A Cloudflare Access protected app still exposes a management portA Cloudflare Access protected app still exposes a management port focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the front door does not automatically secure alternate p...SecurityAdvanced15 minProNETWORK-1351A Cloudflare Tunnel app stays reachable and WebSocket upgrades failA Cloudflare Tunnel app stays reachable and WebSocket upgrades fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Realtime failures behind proxies often come from route-specific header handling r...NetworkAdvanced15 minProNETWORK-1328A Cloudflare Tunnel WebSocket path flakes only on one serviceA service behind Tunnel is healthy for ordinary requests and only its real-time channel fails intermittently after a proxy change.NetworkAdvanced15 minProSECURITY-1334A CrowdSec or Fail2ban style ban pipeline blocks the wrong sourceA CrowdSec or Fail2ban style ban pipeline blocks the wrong source focuses on incident-response and asks the reader to isolate the key signal in NGINX. Security controls that depend on source IP must be reviewed whenever the trust bo...SecurityAdvanced15 minProSECURITY-1308A CSP nonce implementation is correct at origin and still unsafeA team adds CSP nonces and later a cached HTML shell makes the same nonce appear repeatedly in production.SecurityAdvanced15 minProCICD-1364A private registry behind NGINX handles login and small layers fineA private registry behind NGINX handles login and small layers fine focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Path-specific protection can succeed on auth and manifest routes while silently breaking long-l...CI/CDAdvanced15 minProNETWORK-1339A Tunnel and WARP path look healthy and one internal app still failsA Tunnel and WARP path look healthy and one internal app still fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers can be lost after the edge if internal proxy routing is not exp...NetworkAdvanced15 minProSECURITY-1320A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api-client)A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api... focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Parser changes can surface client quirks that were always present but pr...SecurityAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProSECURITY-1330A zero trust policy allows the service token and the backend still returns 403A zero trust policy allows the service token and the backend still returns 403 focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Zero Trust success at the edge does not guarantee the origin app...SecurityAdvanced15 minProNETWORK-1349An NGINX auth flow works for normal pages and Cloudflare Access headers...An NGINX auth flow works for normal pages and Cloudflare Access headers... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity loss behind a proxy often happens on local rewrites long after...NetworkAdvanced15 minProSECURITY-1372An OpenSearch dashboard SSO flow works on GET and failsAn OpenSearch dashboard SSO flow works on GET and fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Cross-site POST returns are especially sensitive to SameSite policy changes around proxy and...SecurityAdvanced15 minProSECURITY-1311A Cloudflare Access policy looks correct and one API still returns 403An internal API is moved behind a new Access application and only some users keep seeing 403 responses from a browser session that otherwise looks authenticated.SecurityAdvanced16 minProSECURITY-1297A rate limiter on login works against direct traffic but notA rate limiter on login works against direct traffic but not focuses on incident-response and asks the reader to isolate the key signal. A rate limiter is only as strong as the identity header or source it trusts.SecurityAdvanced16 minProSECURITY-1262A SameSite cookie setting breaks SSO only on one browser pathSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1295A signed cookie works on one subdomain and fails on anotherA cross-subdomain auth feature works on one hostname and fails only when routed through a CDN alias or alternate domain.SecurityAdvanced16 minProSECURITY-1304A WAF custom rule blocks only the canary URLA security team tunes a WAF rule for production traffic and only the canary path keeps failing with the same signature.SecurityAdvanced16 minPro