Vendor274 problems· 7 reviewed

NGINX

274 incident problems in NGINX environments.

All problems (274)

SECURITY-1374An NGINX auth_request gateway protects normal methods and one CORS preflight...An NGINX auth_request gateway protects normal methods and one CORS... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Method-specific branches in proxies can bypass security logic even when the main path...SecurityAdvanced14 minProNETWORK-1365An NGINX reverse proxy fronting OpenSearch serves queries and bulk ingest...An NGINX reverse proxy fronting OpenSearch serves queries and bulk ingest... focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Healthy read traffic does not prove high-volume write routes kept the sam...NetworkAdvanced14 minProCICD-1340A canary deploy looks healthy in metrics and still fails usersA canary deploy looks healthy in metrics and still fails users focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Healthy internal checks do not prove the external traffic shaping layer is aligned w...CI/CDAdvanced15 minProCICD-1344A Docker registry behind NGINX accepts pushes and later large uploads hangA reverse proxy config is reorganized for clarity and later only larger image pushes start hanging or failing halfway through upload.CI/CDAdvanced15 minProCICD-1374A private registry behind NGINX logs in correctly and larger pushes hangA private registry behind NGINX logs in correctly and larger pushes hang focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Shared security includes can quietly undo streaming behavior required by...CI/CDAdvanced15 minProCICD-1354A registry behind NGINX accepts auth and fails large pushesA registry behind NGINX accepts auth and fails large pushes focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Security includes can accidentally revert performance-critical streaming directives on special...CI/CDAdvanced15 minProNETWORK-1341An NGINX ingress passes health checks and long uploads failAn NGINX ingress passes health checks and long uploads fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Health checks rarely exercise the timeout and buffering profile of the largest request path.NetworkAdvanced15 minProNETWORK-1331An NGINX reverse proxy keeps one upstream marked healthyAn NGINX reverse proxy keeps one upstream marked healthy focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. A healthy keepalive pool can hide failures that only happen on new TLS handshakes.NetworkAdvanced15 minProNETWORK-1336An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk-ingest)An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Edge proxies can be the bottleneck when UI and ingest paths share one...NetworkAdvanced15 minProSECURITY-122A managed WAF rule override expires at midnight UTC, and the payroll batch starts failing in local business hours the next dayThe temporary exception worked during testing, but time-zone assumptions made its expiry far earlier than operators realized.SecurityAdvanced16 minProSECURITY-120The reverse proxy strips HSTS on 304 responses and scanners report an intermittent downgrade riskMost requests include the header, but cache validation paths omit it and some scanners correctly flag the inconsistent transport posture.SecurityAdvanced16 minProSECURITY-103A CSP nonce is generated at the edge, but the application template reuses a stale fragment and browsers block one script bundleThe response headers look correct, yet execution fails because a cached HTML fragment still contains yesterday's nonce value.SecurityAdvanced17 minProLINUX-1288A package postrotate hook restarts the proxy too early and a dependent app loses socket activationA package upgrade modifies runtime layout and later log rotation or restart hooks begin causing downtime instead of harmless reopen events.LinuxAdvanced17 minProSECURITY-136A truststore update keeps the same certificate subject but a new public key, and one mTLS client still pins the old key hashEverything looks like the same identity, yet a deeper trust assumption at the client breaks connectivity.SecurityAdvanced17 minProK8S-105Ingress canary header routing works for HTTP but gRPC requests ignore the split and all traffic stays on stableThe progressive delivery rule appears valid, but the gRPC path follows a different routing evaluation than the header-based HTTP test path.KubernetesAdvanced17 minProSECURITY-129OCSP stapling is healthy at the edge, but the origin health checker trusts only the leaf and marks the backend down on the renewed chainCustomers see a good certificate path, yet the internal monitor fails because its trust assumption is narrower.SecurityAdvanced17 minProSECURITY-252A mutual TLS path validates client chains while one outbound proxy segment blocks CRL or OCSP fetches during a failover rehearsalThe certificate looks correct and revocation checks quietly fail on one leg of the journey. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-147A trust bundle update reaches the API tier, but the sidecar envoy still pins the old bundle hash and east-west mTLS fails only thereCertificate distribution was mostly successful, yet one data-plane component still enforces the previous trust set.SecurityAdvanced18 minProK8S-080Ingress controller leader election lease stayed in the old namespace after a migrationThe new controller deploys cleanly, yet only one replica ever reconciles because the election objects still point at the namespace pattern from the previous release.KubernetesAdvanced18 minProK8S-100Ingress leader election looks healthy but one class still routes nowhereThe controller pods are up, yet routes for one ingress class remain empty because the controller cannot write the status fields other components depend on.KubernetesAdvanced18 minPro