NGINX
274 incident problems in NGINX environments.
먼저 읽을 가이드
추천 문제
All problems (274)
NETWORK-1406A reverse proxy authenticates normal paths and leaks one admin endpointA reverse proxy authenticates normal paths and leaks one admin endpoint focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. Proxy auth gaps often live in normalization order, not in the visible location pattern its...NetworkIntermediate12 minProNETWORK-1370A reverse proxy real-IP fix works for the app and automated bans still hit...A reverse proxy real-IP fix works for the app and automated bans still hit... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Real-IP fixes are incomplete until every security parser reads the same trusted...NetworkIntermediate12 minProNETWORK-1426An auth gateway protects a path and an encoded traversal still reaches the...An auth gateway protects a path and an encoded traversal still reaches the... focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. Path protection bugs often come from normalization order differences rather than fr...NetworkIntermediate12 minProNETWORK-1436An auth gateway protects an admin path and an encoded traversal still reaches itAn encoded admin route variant bypasses the expected auth gateway after a normalization refactor.NetworkIntermediate12 minProNETWORK-1446An auth gateway protects the admin path and an encoded traversal still reaches itAn encoded admin URL bypasses the expected auth gateway after a normalization refactor.NetworkIntermediate12 minProSECURITY-1364An auth_request chain protects the browser UI and one API path bypasses policyA reverse proxy centralizes auth and later only API clients find a path that avoids the expected policy check.SecurityIntermediate12 minProSECURITY-1354An NGINX auth_request policy protects the browser UI and one API route...An NGINX auth_request policy protects the browser UI and one API route... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Auth bypasses often hide in alternate method paths the happy-path browser flow never...SecurityIntermediate12 minProNETWORK-1378Cloudflare Access works on the primary app and the internal admin path loses...Cloudflare Access works on the primary app and the internal admin path... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity propagation can break at internal proxy hops even when the edge...NetworkIntermediate12 minProK8S-1348A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to-https-by-global-annotation)A cert-manager Certificate stays Pending (http01-solver-ingress-forced-to... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Temporary ingress objects can inherit global behaviors that break...KubernetesIntermediate13 minProNETWORK-1368A Cloudflare Access app authenticates correctly and one admin route still...A Cloudflare Access app authenticates correctly and one admin route still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers often disappear inside the origin proxy long after e...NetworkIntermediate13 minProSECURITY-1344An NGINX auth_request chain protects the UI and one API path still bypasses policyA reverse proxy centralizes auth and later only API clients or browser preflight flows can reach one path without the expected policy check.SecurityIntermediate13 minProSECURITY-1333An NGINX auth_request chain works for browsers and fails for API clientsAn NGINX auth_request chain works for browsers and fails for API clients focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Authentication success at the edge does not preserve every authorization s...SecurityIntermediate13 minProNETWORK-1352An NGINX reverse proxy preserves client IP for the app and fail2ban still...An NGINX reverse proxy preserves client IP for the app and fail2ban still... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Fixing forwarded headers is not enough if downstream security automation stil...NetworkIntermediate13 minProNETWORK-1360An OpenSearch cluster behind NGINX serves queries and bulk writes time outAn OpenSearch cluster behind NGINX serves queries and bulk writes time out focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Search health does not prove write paths inherited the same proxy bu...NetworkIntermediate13 minProLINUX-1450A proxy TLS chain looks correct in openssl checks and one app still failsInteractive tests look good while one long-lived client keeps failing validation after a chain update.LinuxAdvanced14 minProNETWORK-1350A reverse proxy fronting OpenSearch stays green and bulk ingest times outAn OpenSearch proxy is reorganized for route clarity and later only bulk ingest begins timing out under load.NetworkIntermediate14 minProSECURITY-1306A SAML logout works on the main domain and loops on the callback pathA reverse proxy serves the same app successfully until logout or ACS validation starts looping under one path.SecurityIntermediate14 minProLINUX-1280A reverse proxy only breaks one websocket clientOne websocket-based UI or client drops repeatedly while ordinary web traffic and even other chatty websocket clients look fine.LinuxIntermediate15 minProLINUX-1289A websocket backend disconnects only for one officeA live dashboard works broadly and disconnects repeatedly only for users behind one corporate network or proxy path.LinuxIntermediate15 minProLINUX-1285Nginx serves the new certificate but OCSP stapling still failsA TLS renewal appears complete and some clients or monitors still report stapling failures after the change.LinuxIntermediate15 minPro