Skip to content

Release 602 - #940

Merged
xschildw merged 8 commits into
developfrom
release-602
Aug 22, 2026
Merged

xschildw merged 8 commits into
developfrom
release-602

Conversation

@xschildw

Copy link
Copy Markdown
Contributor

Not sure why it's showing diffs, all these should already be in dev...

BryanFauble and others added 8 commits August 21, 2026 17:56
…lvable country (SYNSD-2758)

The geo-restriction rule ORs two GeoMatchStatements: one against the request's
raw source IP, one against the IP in X-Forwarded-For with FallbackBehavior set
to MATCH. When that header contains an address AWS WAF can't geolocate (e.g. a
private/reserved-range IP inserted by an intermediate proxy), MATCH treats the
unresolvable header as if it matched a restricted country and blocks the
request, even though the raw source IP resolves to an unrestricted country.

Switching this statement's FallbackBehavior to NO_MATCH removes that false
positive without weakening the restriction: the source-IP-based statement is
independent and still blocks any request whose actual origin geolocates to a
restricted country.
… geo-restriction rule (SYNSD-2758)

The prior fix set the forwarded-IP GeoMatchStatement's FallbackBehavior to
NO_MATCH, which let ANY unresolvable X-Forwarded-For value bypass that
statement, not just the private-IP-behind-a-corporate-proxy case from this
ticket.

Revert FallbackBehavior to MATCH and instead wrap it in an AndStatement with
NOT(IPSetReferenceStatement against a new RFC1918 IPSet), so only forwarded
IPs we can positively confirm are private get excused. Everything else
unresolvable is still blocked, same as before this ticket. The IPSetReferenceStatement
checks X-Forwarded-For (via IPSetForwardedIPConfig) rather than the raw
connection IP, since that's where the private address actually appears; its
own FallbackBehavior is NO_MATCH so an unparseable header is never assumed
private. The raw-source-IP GeoMatchStatement is untouched and remains the
backstop against genuine restricted-country traffic regardless of header
manipulation.
…ed-IP check (SYNSD-2758)

AWS WAF can't geolocate 127.0.0.0/8 (RFC1122 3.2.1.3) any more than it can
geolocate RFC1918 private space, so add it to the IPSet the geo-restriction
rule's NOT(IPSetReferenceStatement) checks against. No production traffic has
been observed hitting this yet, but it's the same class of non-geolocatable
address as the RFC1918 case this ticket was opened for, so exclude it
preemptively. Renamed the IPSet resource from *Rfc1918PrivateIpSet* to
*NonRoutableIpSet* since it now covers more than RFC1918.
…SYNSD-2758)

GeoMatchStatement only ever geolocates the first XFF value, so ANY let a
trailing forged/private value cancel a block on a genuine first-hop match
from a blocked country. Prod WAF logs show no legitimate multi-hop chain
carrying a real geolocatable IP past position 1, so FIRST closes that gap
with no observed cost.
…allback-behavior-602

SYNSD-2758: Only excuse forwarded IPs confirmed RFC1918-private from the geo-restriction rule
@xschildw
xschildw merged commit f124907 into develop Aug 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants