Vendor239 problems· 2 reviewed

Cloudflare

239 incident problems in Cloudflare environments.

All problems (239)

NETWORK-1351A Cloudflare Tunnel app stays reachable and WebSocket upgrades failA Cloudflare Tunnel app stays reachable and WebSocket upgrades fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Realtime failures behind proxies often come from route-specific header handling r...NetworkAdvanced15 minProNETWORK-1328A Cloudflare Tunnel WebSocket path flakes only on one serviceA service behind Tunnel is healthy for ordinary requests and only its real-time channel fails intermittently after a proxy change.NetworkAdvanced15 minProSECURITY-1308A CSP nonce implementation is correct at origin and still unsafeA team adds CSP nonces and later a cached HTML shell makes the same nonce appear repeatedly in production.SecurityAdvanced15 minProNETWORK-1339A Tunnel and WARP path look healthy and one internal app still failsA Tunnel and WARP path look healthy and one internal app still fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers can be lost after the edge if internal proxy routing is not exp...NetworkAdvanced15 minProSECURITY-1320A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api-client)A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api... focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Parser changes can surface client quirks that were always present but pr...SecurityAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProSECURITY-1330A zero trust policy allows the service token and the backend still returns 403A zero trust policy allows the service token and the backend still returns 403 focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Zero Trust success at the edge does not guarantee the origin app...SecurityAdvanced15 minProNETWORK-1349An NGINX auth flow works for normal pages and Cloudflare Access headers...An NGINX auth flow works for normal pages and Cloudflare Access headers... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity loss behind a proxy often happens on local rewrites long after...NetworkAdvanced15 minProSECURITY-1311A Cloudflare Access policy looks correct and one API still returns 403An internal API is moved behind a new Access application and only some users keep seeing 403 responses from a browser session that otherwise looks authenticated.SecurityAdvanced16 minProSECURITY-1304A WAF custom rule blocks only the canary URLA security team tunes a WAF rule for production traffic and only the canary path keeps failing with the same signature.SecurityAdvanced16 minProSECURITY-1303Cloudflare Access protects the app generally and one cached path reaches the origin without identity headersAn origin trusts CF Access headers and later one static-like route starts reaching it without the expected identity context.SecurityAdvanced16 minProSECURITY-1512A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1522A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1492A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minProSECURITY-1502A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minProSECURITY-1473A Cloudflare Access policy allows service tokens and still blocks one routeService-token access works for normal paths and fails only when an upstream sends duplicated slashes.SecurityAdvanced11 minProNETWORK-1477A Cloudflare Access tunnel looks authenticated and still fails WebSocketsAuthenticated WebSockets fail only on one route family behind Cloudflare Tunnel.NetworkAdvanced11 minProNETWORK-1467A Cloudflare Tunnel reconnects repeatedlyCloudflare Tunnel becomes unstable after a firewall policy refactor on the return path.NetworkAdvanced11 minProNETWORK-1553A Cloudflare Tunnel route is active and websocket upgrades still failOnly websocket traffic fails on one connector after origin certificate rotation.NetworkAdvanced11 minProNETWORK-1488A Cloudflare Tunnel upgrade restores websockets and one path still dropsWebSocket sessions still die after a cloudflared upgrade, but only through one proxy path.NetworkAdvanced11 minPro