Back to overview
Resolved

WAF blocking legitimate API requests

May 27, 2026 at 2:41am UTC
Affected services
Ops Network

Resolved
Jun 2, 2026 at 2:44am UTC

Resolved

The mitigation has been successfully deployed across the Ops Network, and this incident has now been fully resolved.

Our monitoring indicates that legitimate API requests are being processed normally and are no longer being incorrectly classified as spam traffic. We have completed our review of the affected traffic and have reached out directly to impacted clients with relevant information regarding requests that were incorrectly blocked during the incident window.

Following deployment, we conducted additional validation and security testing, including simulated distributed denial-of-service (DDoS) and other illegitimate traffic scenarios. These tests confirmed that malicious and unauthorized requests continue to be correctly identified and blocked, while legitimate traffic is processed as expected.

We apologize for the inconvenience caused by this issue and appreciate our clients' patience while our team investigated, mitigated, and resolved the problem. We will continue to review our traffic classification systems and operational processes to help prevent similar incidents in the future.

Updated
May 31, 2026 at 12:28am UTC

Mitigation Deployed

We have successfully implemented a mitigation for the traffic classification issue affecting a subset of API requests within the Ops Network and have begun rolling it out across the network.

The mitigation is designed to prevent legitimate API traffic from being incorrectly identified as spam traffic, reducing the likelihood of unintended blocking, filtering, or rate-limiting behavior. Deployment is proceeding in phases to ensure stability and allow for continuous monitoring throughout the rollout process.

The majority of premium and white-label clients remain unaffected, and client-managed instances and servers within the Ops Network continue to operate normally.

We are closely monitoring the effectiveness of the mitigation and will provide further updates as deployment progresses.

Updated
May 28, 2026 at 4:39am UTC

Identified

Our investigation has identified the source of the issue affecting a subset of API requests within the Ops Network.

Under specific conditions, legitimate API traffic was incorrectly classified as spam traffic, resulting in unintended blocking, filtering, or rate-limiting of affected requests. We have confirmed the root cause and are actively deploying mitigations to reduce impact while we work toward a permanent resolution.

The majority of premium and white-label clients remain unaffected. Client-managed instances and servers operating within the Ops Network are not impacted by this issue.

We will continue to provide updates as mitigation efforts progress and additional improvements are rolled out.

Created
May 27, 2026 at 2:41am UTC

Investigating

We are currently investigating an issue within the Ops Network that may be causing a small subset of legitimate API requests to be incorrectly classified as spam traffic.

Affected requests may experience unexpected blocking, filtering, or rate-limiting behavior. Our engineering team is actively analyzing network traffic and system logs to determine the root cause and scope of the issue.

This incident does not affect the majority of premium or white-label clients, and no client-managed instances or servers within the Ops Network are impacted at this time.

We will provide additional updates as more information becomes available.