Symptoms
When the DOS profile is in use, and a client-side mitigation is active, in some rare cases the request headers were parsed incorrectly, causing valid requests to be reset.
Impact
Some valid requests are blocked during the client-side DOS mitigation.
Conditions
DOS profile is used, DOS attack is active and mitigated using Client-Side Integrity. This is only relevant for the requests which are marked for DOS mitigation.
Fix Information
When mitigating a DOS attack using the Client-Side mitigation, requests with abnormal headers are no longer blocked.