Topic42 problems· 4 reviewed

WAF and AppSec Controls

42 incident problems about WAF and AppSec Controls. Start with the reviewed ones.

All problems (42)

SECURITY-159The mTLS certificate chain validates externally, but the internal proxy strips the client certificate header on HTTP/2 upgrade and backend auth fails only thereTransport security is intact, yet identity propagation across layers is not.SecurityAdvanced17 minProSECURITY-228A custom WAF response hides the real block reason while upstream retries amplify the same exploit attempt internally during a failover rehearsalThe control works and one observability decision turns it into operational noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-324A mutual TLS path validates at the edge while revocation checks or identity forwarding fail later in the request chain during a failover rehearsalTransport setup succeeds and the secure identity contract breaks farther downstream. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-139The reverse proxy and WAF normalize duplicate headers differently, creating a request-smuggling edge case on one legacy routeMost paths are safe, but one parsing mismatch keeps a classic multi-hop ambiguity alive.SecurityAdvanced18 minProSECURITY-174Two request-processing layers normalize the same input differently and one legacy route stays bypassable during a failover rehearsalMultiple security layers inspect the request and disagree on what the request really is. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-084WAF JSON parser normalizes the body differently from the application and bypasses the intended block ruleSecurity rules appear present, but a crafted request still reaches the app because the protection layer interprets the JSON structure differently from the backend.SecurityAdvanced21 minProSECURITY-057Certificate pinning fails only on the guest network after SSL inspection is enabledThe app works on trusted networks, but mobile users on the guest path fail because the intercepted certificate no longer matches the pinned expectation.SecurityAdvanced22 minProSECURITY-053CSP nonce is generated correctly but disappears after CDN template cachingThe application renders a fresh nonce, yet the browser still blocks the script because the cached edge fragment reuses a stale header-body combination.SecurityAdvanced23 minProSECURITY-038CDN caches an authenticated error pageThe login path itself is correct, but one personalized failure response gets cached at the edge and leaks confusing content to later users.SecurityAdvanced24 minProSECURITY-040New allow rule never takes effectOperators add the expected allow rule for an update feed or admin flow, but traffic still fails because an earlier broader deny or different zone match wins first.SecurityAdvanced25 minProSECURITY-027Egress proxy bypass remains possible through one legacy hostnameMost outbound traffic now uses the secured path, but an overlooked legacy name still resolves around the expected control point.SecurityAdvanced27 minProSECURITY-003WAF rule deployment blocks admin API but misses the real attack pathA hotfix rule stops valid management traffic while the malicious request pattern still finds an unprotected endpoint.SecurityAdvanced28 minProSECURITY-122A managed WAF rule override expires at midnight UTC, and the payroll batch starts failing in local business hours the next dayThe temporary exception worked during testing, but time-zone assumptions made its expiry far earlier than operators realized.SecurityAdvanced16 minProSECURITY-120The reverse proxy strips HSTS on 304 responses and scanners report an intermittent downgrade riskMost requests include the header, but cache validation paths omit it and some scanners correctly flag the inconsistent transport posture.SecurityAdvanced16 minProSECURITY-103A CSP nonce is generated at the edge, but the application template reuses a stale fragment and browsers block one script bundleThe response headers look correct, yet execution fails because a cached HTML fragment still contains yesterday's nonce value.SecurityAdvanced17 minProSECURITY-155A DLP sensor classifies the document correctly, but a newly compressed archive format bypasses the extraction depth limit and the policy never sees the payloadContent controls are configured, yet packaging format changed the scanner's visibility boundary.SecurityAdvanced17 minProSECURITY-312A browser isolation or proxy layer protects the main UI while websocket or export paths bypass the protected route entirely during a failover rehearsalThe most visible path is controlled and a lower-visibility path still leaks data or interactivity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-011Reverse proxy strips security header needed for SSO callbackThe identity provider finishes correctly, but the application rejects the callback because a forwarded security header never arrives.SecurityIntermediate22 minProSECURITY-026Security scanner flags admin port exposure only on standby nodeThe active node looks protected, but a standby or failover host still exposes the management service to a wider segment.SecurityIntermediate20 minPro