Summary
HTTP 5xx alert Zava-http-5xx-errors (Sev2) fired at 2026-06-23T01:06:16Z on Application Insights resource ai-zava-auf6gw in rg-zava-aks-postgres. Investigation confirmed that 3 HTTP 503 errors were caused by a QualysGuard vulnerability scanner (IP 20.109.165.83) sending requests with non-integer product IDs (phpPhotoAlbum, bad397) to the /api/products/{id} endpoint. The API passes these strings directly to PostgreSQL without input validation, triggering PostgreSQL error 22P02 (invalid input syntax for type integer), which surfaces as HTTP 503 instead of the correct 400 Bad Request.
This is NOT an infrastructure outage — PostgreSQL is Ready, AKS is Running, and no manual changes were detected. This is a code-level input validation bug exposed by scanner traffic.
Impact
| Metric |
Value |
| Total 5xx errors |
3 |
| Time window |
2026-06-23 01:07:00 – 01:07:59 UTC |
| Affected endpoints |
GET /api/products/phpPhotoAlbum, GET /api/products/bad397, GET /products/phpPhotoAlbum/ |
| Total requests in window |
2,186 |
| Success rate |
99.86% |
| Legitimate user impact |
None — all 503s from scanner traffic |
| Avg response time (5xx) |
8.2 ms |
Timeline
| Time (UTC) |
Event |
| 00:59:23 |
QualysGuard scanner (UA: "QualysGuard") begins probing from IP 20.109.165.83 |
| 01:02–01:03 |
Scanner probes common vulnerability paths (/CSCOSSLC/config-auth, /DeviceInformation, /cgi-bin/) — all return 404 |
| 01:05–01:06 |
Scanner activity escalates: SSL cipher probes, path traversal probes (~252 req/min at 01:06) |
| 01:06:16 |
Alert fired: Zava-http-5xx-errors (Sev2) |
| 01:06:41 |
SSL handshake failure logged: SSL_do_handshake() failed (required cipher missing) |
| 01:07:36 |
Scanner sends malformed If-Match: * request → 400 |
| 01:07:58 |
Scanner hits /products/phpPhotoAlbum/ → frontend routes to /api/products/phpPhotoAlbum → PostgreSQL 22P02 → HTTP 503 |
| 01:07:58 |
Scanner hits /products/bad397/ → same error chain → HTTP 503 |
| 01:07:58 |
App log: "Failed to fetch product detail", "invalid input syntax for type integer: \"phpPhotoAlbum\"" |
| 01:08:00 |
Scanner activity peaks at 1,756 req/min — all subsequent requests hit valid paths or return 404 |
| 01:09:00 |
Scanner activity subsides to 697 req/min |
| 01:11:00 |
Alert investigation started by SRE Agent |
Evidence
1. AppRequests — 5xx Errors (Log Analytics)
TimeGenerated | ResultCode | Name | Count | AvgDurationMs
2026-06-23T01:07:00Z | 503 | GET /api/products/phpPhotoAlbum | 1 | 4.65
2026-06-23T01:07:00Z | 503 | GET /api/products/bad397 | 1 | 6.40
2026-06-23T01:07:00Z | 503 | GET /products/phpPhotoAlbum/ | 1 | 13.63
2. AppExceptions — PostgreSQL Error 22P02
TimeGenerated | ExceptionType | Message
2026-06-23T01:07:58.649Z | undefined | PostgreSQL error of type 'error' occurred (code: 22P02)
2026-06-23T01:07:58.458Z | undefined | PostgreSQL error of type 'error' occurred (code: 22P02)
3. Container Logs — Error Chain
{"level":"error","message":"Failed to fetch product detail","error":"invalid input syntax for type integer: \"phpPhotoAlbum\"","productId":"phpPhotoAlbum"}
{"level":"info","message":"GET /api/products/phpPhotoAlbum","statusCode":503,"duration_ms":4}
{"level":"error","message":"Product detail fetch failed","error":"Request failed with status code 503","productId":"phpPhotoAlbum"}
4. Scanner Source Identification
User-Agent: QualysGuard
Source IP: 20.109.165.83
Probed paths: /CSCOSSLC/config-auth, /DeviceInformation, /CGI/Java/Serviceability, /cgi-bin/,
/php/login.php, /js/pan/base/cookie.js, /sysmgmt/2015/bmc/info, /login, SSL cipher probes
Peak traffic: 1,756 req/min at 01:08 UTC
5. Infrastructure Health (No Issues)
PostgreSQL zava-pg-auf6gw: state = Ready
AKS aks-Zava-auf6gw: powerState = Running
Activity Log: No write/action events in the 4h window
AppRequests success rate (excl. scanner 503s): 100%
6. Request Volume Timeline (Last Hour)
- 00:09–01:04 UTC: Steady ~230-250 req/min, 0 failures, 100% success rate
- 01:05 UTC: Request volume starts climbing (284 req/min) — scanner begins
- 01:06 UTC: 445 req/min, 0 failures
- 01:07 UTC: 536 req/min, 3 failures (99.44% success rate) — scanner hits
/products/{non-integer-id}
- 01:08 UTC: 810 req/min (peak), 0 failures
- 01:09 UTC: 574 req/min, 0 failures
Root Cause
Primary: Missing input validation on the /api/products/:id endpoint in the zava-api service. The product ID parameter is passed directly to a PostgreSQL query expecting an integer type. When a non-integer string (e.g., phpPhotoAlbum) is provided, PostgreSQL throws error code 22P02 (invalid input syntax for type integer). The application does not catch this error gracefully, resulting in an HTTP 503 Service Unavailable response instead of the correct 400 Bad Request.
Trigger: QualysGuard vulnerability scanner probing the application with common attack paths, some of which get routed through the frontend to /api/products/{string-id}.
Error Chain:
Scanner → GET /products/phpPhotoAlbum/ → Frontend routes to GET /api/products/phpPhotoAlbum
→ API passes "phpPhotoAlbum" to PostgreSQL → PG error 22P02 (invalid input syntax for type integer)
→ Unhandled exception → HTTP 503
Remediation
Immediate (No Action Required)
- Impact is negligible — only 3 requests from scanner traffic, no legitimate users affected
- Infrastructure is healthy — no restart, scaling, or mitigation needed
- The scanner activity has subsided
Short-Term (Code Fix — P3)
- Add input validation on the
/api/products/:id route — validate that id is a valid integer before querying PostgreSQL
- Return HTTP 400 (Bad Request) with a descriptive error message for non-integer product IDs
- Add try-catch around the PostgreSQL query to handle
22P02 errors gracefully
Medium-Term (Hardening — P4)
- Add WAF rules or rate limiting to throttle/block known vulnerability scanner traffic
- Add input validation middleware across all API endpoints that accept typed parameters
- Improve error handling — ensure all PostgreSQL errors map to appropriate HTTP status codes (4xx for client errors, 5xx only for server errors)
Action Items
References
| Resource |
ID/Value |
| Alert ID |
/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourcegroups/rg-zava-aks-postgres/providers/microsoft.insights/components/ai-zava-auf6gw/providers/Microsoft.AlertsManagement/alerts/93dae6d4-31f5-478a-9731-819c0e1bf000 |
| Alert Rule |
Zava-http-5xx-errors |
| App Insights Resource ID |
/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.Insights/components/ai-zava-auf6gw |
| Log Analytics Workspace ID |
69f6cc9c-c59f-4624-8b95-e12b93220ece |
| PostgreSQL Server |
/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.DBforPostgreSQL/flexibleServers/zava-pg-auf6gw |
| AKS Cluster |
/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.ContainerService/managedClusters/aks-Zava-auf6gw |
| Subscription |
f627598e-05c5-4093-8667-5730c4026ea3 |
| Resource Group |
rg-zava-aks-postgres |
| Scanner Source IP |
20.109.165.83 |
| Scanner User-Agent |
QualysGuard |
Investigated by Azure SRE Agent | Alert fired 2026-06-23T01:06:16Z | Investigation completed 2026-06-23T01:13:00Z
This issue was created by sre-agent-jkazytu5kl5py--70975bf6
Tracked by the SRE agent here
Summary
HTTP 5xx alert
Zava-http-5xx-errors(Sev2) fired at 2026-06-23T01:06:16Z on Application Insights resourceai-zava-auf6gwinrg-zava-aks-postgres. Investigation confirmed that 3 HTTP 503 errors were caused by a QualysGuard vulnerability scanner (IP20.109.165.83) sending requests with non-integer product IDs (phpPhotoAlbum,bad397) to the/api/products/{id}endpoint. The API passes these strings directly to PostgreSQL without input validation, triggering PostgreSQL error22P02(invalid input syntax for type integer), which surfaces as HTTP 503 instead of the correct 400 Bad Request.This is NOT an infrastructure outage — PostgreSQL is Ready, AKS is Running, and no manual changes were detected. This is a code-level input validation bug exposed by scanner traffic.
Impact
GET /api/products/phpPhotoAlbum,GET /api/products/bad397,GET /products/phpPhotoAlbum/Timeline
20.109.165.83/CSCOSSLC/config-auth,/DeviceInformation,/cgi-bin/) — all return 404Zava-http-5xx-errors(Sev2)SSL_do_handshake() failed (required cipher missing)If-Match: *request → 400/products/phpPhotoAlbum/→ frontend routes to/api/products/phpPhotoAlbum→ PostgreSQL 22P02 → HTTP 503/products/bad397/→ same error chain → HTTP 503"Failed to fetch product detail","invalid input syntax for type integer: \"phpPhotoAlbum\""Evidence
1. AppRequests — 5xx Errors (Log Analytics)
2. AppExceptions — PostgreSQL Error 22P02
3. Container Logs — Error Chain
{"level":"error","message":"Failed to fetch product detail","error":"invalid input syntax for type integer: \"phpPhotoAlbum\"","productId":"phpPhotoAlbum"} {"level":"info","message":"GET /api/products/phpPhotoAlbum","statusCode":503,"duration_ms":4} {"level":"error","message":"Product detail fetch failed","error":"Request failed with status code 503","productId":"phpPhotoAlbum"}4. Scanner Source Identification
5. Infrastructure Health (No Issues)
6. Request Volume Timeline (Last Hour)
/products/{non-integer-id}Root Cause
Primary: Missing input validation on the
/api/products/:idendpoint in thezava-apiservice. The product ID parameter is passed directly to a PostgreSQL query expecting an integer type. When a non-integer string (e.g.,phpPhotoAlbum) is provided, PostgreSQL throws error code22P02(invalid input syntax for type integer). The application does not catch this error gracefully, resulting in an HTTP 503 Service Unavailable response instead of the correct 400 Bad Request.Trigger: QualysGuard vulnerability scanner probing the application with common attack paths, some of which get routed through the frontend to
/api/products/{string-id}.Error Chain:
Remediation
Immediate (No Action Required)
Short-Term (Code Fix — P3)
/api/products/:idroute — validate thatidis a valid integer before querying PostgreSQL22P02errors gracefullyMedium-Term (Hardening — P4)
Action Items
/api/products/:idendpoint — validate integer, return 400 for invalid input22P02errors to return 400 instead of 503References
/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourcegroups/rg-zava-aks-postgres/providers/microsoft.insights/components/ai-zava-auf6gw/providers/Microsoft.AlertsManagement/alerts/93dae6d4-31f5-478a-9731-819c0e1bf000Zava-http-5xx-errors/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.Insights/components/ai-zava-auf6gw69f6cc9c-c59f-4624-8b95-e12b93220ece/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.DBforPostgreSQL/flexibleServers/zava-pg-auf6gw/subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.ContainerService/managedClusters/aks-Zava-auf6gwf627598e-05c5-4093-8667-5730c4026ea3rg-zava-aks-postgres20.109.165.83QualysGuardInvestigated by Azure SRE Agent | Alert fired 2026-06-23T01:06:16Z | Investigation completed 2026-06-23T01:13:00Z
This issue was created by sre-agent-jkazytu5kl5py--70975bf6
Tracked by the SRE agent here