Topic163 problems

Reverse Proxy Security

163 incident problems about Reverse Proxy Security. Start with the reviewed ones.

All problems (163)

NETWORK-1320A Cloudflare WARP to Tunnel path reaches the origin and application auth...A Cloudflare WARP to Tunnel path reaches the origin and application auth... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Path success through Zero Trust does not prove origin ACLs recognize the new caller...NetworkAdvanced16 minProSECURITY-1284A new WAF rule blocks only file uploadsA WAF tuning change appears safe until one upload-heavy path begins failing only after a CDN or edge normalization update.SecurityIntermediate16 minProNETWORK-1312A Palo Alto decryption policy excludes the hostname and traffic still breaksA Palo Alto decryption policy excludes the hostname and traffic still breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. Pinned apps can fail on regional certificate differences even when h...NetworkAdvanced16 minProSECURITY-1267A SameSite cookie setting breaks SSO only on one browser pathA browser-specific SSO failure appears after cookie hardening, while the same app still works through simpler redirect paths.SecurityIntermediate16 minProK8S-1328A Traefik TCP route disappears only after a second team adds another serviceA cluster exposes multiple TCP services and one of them vanishes after another team deploys a new route on the same entryPoint.KubernetesAdvanced16 minProK8S-1314An ingress migration preserves the hostname and still failsAn ingress migration preserves the hostname and still fails focuses on Deployment Governance and asks the reader to isolate the key signal in Kubernetes. Controller migrations preserve intent less faithfully than YAML similarity suggests.KubernetesAdvanced16 minProNETWORK-1302An SSL decryption exception seems broad enough and still breaks one mobile appA mobile app breaks after decryption is enabled even though the visible hostname was already exempted.NetworkAdvanced16 minProSECURITY-1291A JWKS rotation is complete but one consumer still failsA token issuer rotates keys and one consumer behind a proxy continues rejecting fresh tokens.SecurityAdvanced17 minProSECURITY-1289A JWT audience check passes in staging but fails in productionAuthentication works end-to-end in staging and fails only in production behind an API gateway performing token exchange or translation.SecurityAdvanced17 minProLINUX-1298A SELinux boolean change fixes one service and breaks anotherTwo services share a host path and a fast SELinux fix for one later causes unexplained failures in the other.LinuxAdvanced17 minProSECURITY-1281An OAuth callback succeeds on the identity provider but the app rejects the...An OAuth callback succeeds on the identity provider but the app rejects the... focuses on Identity And Access and asks the reader to isolate the key signal. OIDC callback bugs can be reverse-proxy identity bugs wearing an auth mask.SecurityAdvanced17 minProSECURITY-1241A login loop persists after a successful OIDC callbackOne hostname or browser completes the login flow while another loops indefinitely even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1246An OIDC login loop continues after a successful callbackOne hostname or browser completes the sign-in flow and another loops forever even though the provider logs a successful callback.SecurityAdvanced18 minProSECURITY-1251An OIDC login loop persists after a successful callbackOne browser or hostname signs in successfully while another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1256OIDC login succeeds at the provider but loops at the appOne login URL works while another hostname for the same app loops forever despite identical provider-side configuration.SecurityAdvanced18 minProSECURITY-1226OIDC login works in one browser but fails in anotherA login flow appears healthy in one hostname path or browser and fails with state or nonce errors in another.SecurityAdvanced18 minProSECURITY-1202Scanner still sees an exposed admin routeA reverse-proxy rule from community examples protects the obvious admin path. Scanning still finds exposure because a normalized variant resolves through another rule path.SecurityIntermediate18 minProSECURITY-1197Security scan reports a public admin routeA route looks protected in manual testing, yet a scan still reaches the admin path because one redirect or normalized path bypasses the auth requirement.SecurityIntermediate18 minProSECURITY-1194Basic auth on one route hides that the file-upload path uses a different location blockThe visible admin page is protected, but the upload path still reaches the backend unauthenticated because it matches another location rule.SecurityIntermediate19 minProSECURITY-1182Fail2ban blocks trusted health checksA public Fail2ban recipe is copied into a reverse-proxy deployment and legitimate checks start getting banned as if they were attacks.SecurityIntermediate19 minPro