Vendor274 problems· 7 reviewed

NGINX

274 incident problems in NGINX environments.

All problems (274)

SECURITY-159The mTLS certificate chain validates externally, but the internal proxy strips the client certificate header on HTTP/2 upgrade and backend auth fails only thereTransport security is intact, yet identity propagation across layers is not.SecurityAdvanced17 minProSECURITY-228A custom WAF response hides the real block reason while upstream retries amplify the same exploit attempt internally during a failover rehearsalThe control works and one observability decision turns it into operational noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-324A mutual TLS path validates at the edge while revocation checks or identity forwarding fail later in the request chain during a failover rehearsalTransport setup succeeds and the secure identity contract breaks farther downstream. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProSECURITY-094mTLS handshake succeeds to the proxy but upstream certificate pinning breaks only on one pathThe edge trust path looks correct, yet the service still fails because an internal hop enforces a different certificate identity contract.SecurityAdvanced18 minProSECURITY-139The reverse proxy and WAF normalize duplicate headers differently, creating a request-smuggling edge case on one legacy routeMost paths are safe, but one parsing mismatch keeps a classic multi-hop ambiguity alive.SecurityAdvanced18 minProSECURITY-174Two request-processing layers normalize the same input differently and one legacy route stays bypassable during a failover rehearsalMultiple security layers inspect the request and disagree on what the request really is. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-088Mutual TLS is enabled but the CRL endpoint is unreachable and only strict clients reject the serverCertificates are otherwise valid, but some clients fail because they require revocation checking and the CRL distribution path is no longer reachable.SecurityAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProK8S-081Readiness passes but Envoy sidecar cannot reach the control plane after a trust bundle splitThe app container is healthy, yet traffic still fails because the sidecar lost trust in the mesh control plane after the certificate bundle changed unevenly.KubernetesAdvanced21 minProSECURITY-084WAF JSON parser normalizes the body differently from the application and bypasses the intended block ruleSecurity rules appear present, but a crafted request still reaches the app because the protection layer interprets the JSON structure differently from the backend.SecurityAdvanced21 minProSECURITY-1210mTLS rotation looks complete but one gateway still failsAn mTLS rotation completes and most gateways recover, but one still rejects peers because its chain trust is incomplete.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProSECURITY-053CSP nonce is generated correctly but disappears after CDN template cachingThe application renders a fresh nonce, yet the browser still blocks the script because the cached edge fragment reuses a stale header-body combination.SecurityAdvanced23 minProSECURITY-038CDN caches an authenticated error pageThe login path itself is correct, but one personalized failure response gets cached at the edge and leaks confusing content to later users.SecurityAdvanced24 minProSECURITY-003WAF rule deployment blocks admin API but misses the real attack pathA hotfix rule stops valid management traffic while the malicious request pattern still finds an unprotected endpoint.SecurityAdvanced28 minProNETWORK-1601An NGINX proxy fix is correct and one backend still sees the wrong client chainOne backend still sees the wrong client chain after an NGINX proxy fix.NetworkAdvanced9 minProNETWORK-1591An NGINX real_ip fix lands and one host still logs the old sourceOne host still logs the old source IP after a real_ip fix.NetworkAdvanced9 minProK8S-1593A Gateway API route changes and one listener still serves the old backendOne listener still serves the old backend after a Gateway API route change.KubernetesAdvanced10 minPro