Skip to content

[Incident] Zava HTTP 5xx Errors — QualysGuard Scanner Triggering Input Validation Bug (2026-06-23) #5

Description

@wilkinshum

Summary

HTTP 5xx alert Zava-http-5xx-errors (Sev2) fired at 2026-06-23T01:06:16Z on Application Insights resource ai-zava-auf6gw in rg-zava-aks-postgres. Investigation confirmed that 3 HTTP 503 errors were caused by a QualysGuard vulnerability scanner (IP 20.109.165.83) sending requests with non-integer product IDs (phpPhotoAlbum, bad397) to the /api/products/{id} endpoint. The API passes these strings directly to PostgreSQL without input validation, triggering PostgreSQL error 22P02 (invalid input syntax for type integer), which surfaces as HTTP 503 instead of the correct 400 Bad Request.

This is NOT an infrastructure outage — PostgreSQL is Ready, AKS is Running, and no manual changes were detected. This is a code-level input validation bug exposed by scanner traffic.

Impact

Metric Value
Total 5xx errors 3
Time window 2026-06-23 01:07:00 – 01:07:59 UTC
Affected endpoints GET /api/products/phpPhotoAlbum, GET /api/products/bad397, GET /products/phpPhotoAlbum/
Total requests in window 2,186
Success rate 99.86%
Legitimate user impact None — all 503s from scanner traffic
Avg response time (5xx) 8.2 ms

Timeline

Time (UTC) Event
00:59:23 QualysGuard scanner (UA: "QualysGuard") begins probing from IP 20.109.165.83
01:02–01:03 Scanner probes common vulnerability paths (/CSCOSSLC/config-auth, /DeviceInformation, /cgi-bin/) — all return 404
01:05–01:06 Scanner activity escalates: SSL cipher probes, path traversal probes (~252 req/min at 01:06)
01:06:16 Alert fired: Zava-http-5xx-errors (Sev2)
01:06:41 SSL handshake failure logged: SSL_do_handshake() failed (required cipher missing)
01:07:36 Scanner sends malformed If-Match: * request → 400
01:07:58 Scanner hits /products/phpPhotoAlbum/ → frontend routes to /api/products/phpPhotoAlbum → PostgreSQL 22P02 → HTTP 503
01:07:58 Scanner hits /products/bad397/ → same error chain → HTTP 503
01:07:58 App log: "Failed to fetch product detail", "invalid input syntax for type integer: \"phpPhotoAlbum\""
01:08:00 Scanner activity peaks at 1,756 req/min — all subsequent requests hit valid paths or return 404
01:09:00 Scanner activity subsides to 697 req/min
01:11:00 Alert investigation started by SRE Agent

Evidence

1. AppRequests — 5xx Errors (Log Analytics)

TimeGenerated           | ResultCode | Name                            | Count | AvgDurationMs
2026-06-23T01:07:00Z    | 503        | GET /api/products/phpPhotoAlbum  | 1     | 4.65
2026-06-23T01:07:00Z    | 503        | GET /api/products/bad397         | 1     | 6.40
2026-06-23T01:07:00Z    | 503        | GET /products/phpPhotoAlbum/     | 1     | 13.63

2. AppExceptions — PostgreSQL Error 22P02

TimeGenerated            | ExceptionType | Message
2026-06-23T01:07:58.649Z | undefined     | PostgreSQL error of type 'error' occurred (code: 22P02)
2026-06-23T01:07:58.458Z | undefined     | PostgreSQL error of type 'error' occurred (code: 22P02)

3. Container Logs — Error Chain

{"level":"error","message":"Failed to fetch product detail","error":"invalid input syntax for type integer: \"phpPhotoAlbum\"","productId":"phpPhotoAlbum"}
{"level":"info","message":"GET /api/products/phpPhotoAlbum","statusCode":503,"duration_ms":4}
{"level":"error","message":"Product detail fetch failed","error":"Request failed with status code 503","productId":"phpPhotoAlbum"}

4. Scanner Source Identification

User-Agent: QualysGuard
Source IP: 20.109.165.83
Probed paths: /CSCOSSLC/config-auth, /DeviceInformation, /CGI/Java/Serviceability, /cgi-bin/,
              /php/login.php, /js/pan/base/cookie.js, /sysmgmt/2015/bmc/info, /login, SSL cipher probes
Peak traffic: 1,756 req/min at 01:08 UTC

5. Infrastructure Health (No Issues)

PostgreSQL zava-pg-auf6gw: state = Ready
AKS aks-Zava-auf6gw: powerState = Running
Activity Log: No write/action events in the 4h window
AppRequests success rate (excl. scanner 503s): 100%

6. Request Volume Timeline (Last Hour)

  • 00:09–01:04 UTC: Steady ~230-250 req/min, 0 failures, 100% success rate
  • 01:05 UTC: Request volume starts climbing (284 req/min) — scanner begins
  • 01:06 UTC: 445 req/min, 0 failures
  • 01:07 UTC: 536 req/min, 3 failures (99.44% success rate) — scanner hits /products/{non-integer-id}
  • 01:08 UTC: 810 req/min (peak), 0 failures
  • 01:09 UTC: 574 req/min, 0 failures

Root Cause

Primary: Missing input validation on the /api/products/:id endpoint in the zava-api service. The product ID parameter is passed directly to a PostgreSQL query expecting an integer type. When a non-integer string (e.g., phpPhotoAlbum) is provided, PostgreSQL throws error code 22P02 (invalid input syntax for type integer). The application does not catch this error gracefully, resulting in an HTTP 503 Service Unavailable response instead of the correct 400 Bad Request.

Trigger: QualysGuard vulnerability scanner probing the application with common attack paths, some of which get routed through the frontend to /api/products/{string-id}.

Error Chain:

Scanner → GET /products/phpPhotoAlbum/ → Frontend routes to GET /api/products/phpPhotoAlbum
→ API passes "phpPhotoAlbum" to PostgreSQL → PG error 22P02 (invalid input syntax for type integer)
→ Unhandled exception → HTTP 503

Remediation

Immediate (No Action Required)

  • Impact is negligible — only 3 requests from scanner traffic, no legitimate users affected
  • Infrastructure is healthy — no restart, scaling, or mitigation needed
  • The scanner activity has subsided

Short-Term (Code Fix — P3)

  1. Add input validation on the /api/products/:id route — validate that id is a valid integer before querying PostgreSQL
  2. Return HTTP 400 (Bad Request) with a descriptive error message for non-integer product IDs
  3. Add try-catch around the PostgreSQL query to handle 22P02 errors gracefully

Medium-Term (Hardening — P4)

  1. Add WAF rules or rate limiting to throttle/block known vulnerability scanner traffic
  2. Add input validation middleware across all API endpoints that accept typed parameters
  3. Improve error handling — ensure all PostgreSQL errors map to appropriate HTTP status codes (4xx for client errors, 5xx only for server errors)

Action Items

  • P3: Fix product ID input validation in /api/products/:id endpoint — validate integer, return 400 for invalid input
  • P3: Add error handling for PostgreSQL 22P02 errors to return 400 instead of 503
  • P4: Add input validation middleware for all typed API parameters
  • P4: Evaluate WAF rules for scanner traffic on the AKS ingress
  • P4: Review and harden all API endpoints against non-integer input injection

References

Resource ID/Value
Alert ID /subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourcegroups/rg-zava-aks-postgres/providers/microsoft.insights/components/ai-zava-auf6gw/providers/Microsoft.AlertsManagement/alerts/93dae6d4-31f5-478a-9731-819c0e1bf000
Alert Rule Zava-http-5xx-errors
App Insights Resource ID /subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.Insights/components/ai-zava-auf6gw
Log Analytics Workspace ID 69f6cc9c-c59f-4624-8b95-e12b93220ece
PostgreSQL Server /subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.DBforPostgreSQL/flexibleServers/zava-pg-auf6gw
AKS Cluster /subscriptions/f627598e-05c5-4093-8667-5730c4026ea3/resourceGroups/rg-zava-aks-postgres/providers/Microsoft.ContainerService/managedClusters/aks-Zava-auf6gw
Subscription f627598e-05c5-4093-8667-5730c4026ea3
Resource Group rg-zava-aks-postgres
Scanner Source IP 20.109.165.83
Scanner User-Agent QualysGuard

Investigated by Azure SRE Agent | Alert fired 2026-06-23T01:06:16Z | Investigation completed 2026-06-23T01:13:00Z

This issue was created by sre-agent-jkazytu5kl5py--70975bf6
Tracked by the SRE agent here

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions