Reverse Proxy Security
163 incident problems about Reverse Proxy Security. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (163)
SECURITY-1190Scanner reports the upload path is openA basic-auth recipe from community forums was added to NGINX. The visible admin UI is protected, but an adjacent upload path still reaches the backend unauthenticated.SecurityIntermediate19 minProSECURITY-1196JWT validation fails only on one proxy pathA key rotation followed public best practices. One proxy path still rejects tokens because it holds an older JWKS view than the rest of the platform.SecurityAdvanced21 minProNETWORK-1210HTTPS health checks pass on one hostname while the real route failsAn edge service returns healthy responses to probes on one host name, while customers still see TLS errors on another.NetworkAdvanced22 minProK8S-1209One ingress route still breaks WebSocket upgradesA platform keeps WebSockets behind ingress plus an edge proxy and only one upgraded route returns 400.KubernetesAdvanced23 minProNETWORK-1398A load balancer monitor says healthy and clients fail POST requestsA load balancer monitor says healthy and clients fail POST requests focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Health checks often overestimate availability when they bypass the security or...NetworkIntermediate10 minProNETWORK-1386A Cloudflare page rule or transform looks correct and one admin path still bypasses authA transform rules rollout simplifies URLs and later only one protected path begins bypassing the expected edge auth behavior.NetworkIntermediate11 minProNETWORK-1394A TCP stream proxy still passes traffic and client IP allowlists failA TCP stream proxy still passes traffic and client IP allowlists fail focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Source identity failures can come from protocol version mismatch even when tr...NetworkIntermediate11 minProNETWORK-1396An edge auth rule should block a path and one localized URL stays openA multilingual or encoded URL path reaches an origin route that should have been blocked by edge auth.NetworkIntermediate11 minProNETWORK-1384An NGINX stream proxy accepts TLS and backend auth breaksAn NGINX stream proxy accepts TLS and backend auth breaks focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Proxy protocol misalignment often shows up as auth or allowlist failures rather th...NetworkIntermediate11 minProK8S-1378A cert-manager HTTP01 challenge failsA global ingress annotation cleanup lands and later only HTTP01 certificate renewals begin to fail.KubernetesIntermediate12 minProK8S-1368A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global-https-redirect)A cert-manager HTTP01 challenge fails (http01-solver-ingress-inherited-global... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary challenge routes can inherit cluster-wide ingress behavio...KubernetesIntermediate12 minProNETWORK-1373A Cloudflare tunnel path works over TCP and one browser class still failsA secure tunnel works after an inspection exception and later a subset of browsers or clients still fail to connect reliably.NetworkIntermediate12 minProNETWORK-1379A HA sync succeeds and a package upgrade still breaks TLSAn HA pair survives a software upgrade and later failover lands on a node that cannot present the expected certificate chain.NetworkIntermediate12 minProNETWORK-1370A reverse proxy real-IP fix works for the app and automated bans still hit...A reverse proxy real-IP fix works for the app and automated bans still hit... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Real-IP fixes are incomplete until every security parser reads the same trusted...NetworkIntermediate12 minProSECURITY-1364An auth_request chain protects the browser UI and one API path bypasses policyA reverse proxy centralizes auth and later only API clients find a path that avoids the expected policy check.SecurityIntermediate12 minProSECURITY-1354An NGINX auth_request policy protects the browser UI and one API route...An NGINX auth_request policy protects the browser UI and one API route... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Auth bypasses often hide in alternate method paths the happy-path browser flow never...SecurityIntermediate12 minProNETWORK-1378Cloudflare Access works on the primary app and the internal admin path loses...Cloudflare Access works on the primary app and the internal admin path... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity propagation can break at internal proxy hops even when the edge...NetworkIntermediate12 minProK8S-1348A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to-https-by-global-annotation)A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary ingress objects can inherit global behaviors that break...KubernetesIntermediate13 minProNETWORK-1368A Cloudflare Access app authenticates correctly and one admin route still...A Cloudflare Access app authenticates correctly and one admin route still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers often disappear inside the origin proxy long after e...NetworkIntermediate13 minProNETWORK-1333A Cloudflare cache purge appears successful and one path still serves stale...A Cloudflare cache purge appears successful and one path still serves stale... focuses on Deployment Governance and asks the reader to isolate the key signal in Cloudflare. A successful purge response does not prove it targeted the same cache identity m...NetworkIntermediate13 minPro