Fluid Attacks incident

Fix generation failure due to timeout

Notice Resolved View vendor source →

Fluid Attacks experienced a notice incident on November 12, 2025 affecting Platform and Extensions, lasting 2h 44m. The incident has been resolved; the full update timeline is below.

Started
Nov 12, 2025, 09:00 PM UTC
Resolved
Nov 12, 2025, 11:45 PM UTC
Duration
2h 44m
Detected by Pingoru
Nov 12, 2025, 09:00 PM UTC

Affected components

PlatformExtensions

Update timeline

  1. identified Nov 18, 2025, 03:38 PM UTC

    It has been identified that Fixes are not being generated in the extension or the platform due to an “Endpoint request timed out” error.

  2. resolved Nov 18, 2025, 03:42 PM UTC

    The incident has been resolved, and fix generation within the extensions and the platform has been restored to normal operation.

  3. postmortem Nov 18, 2025, 03:49 PM UTC

    **Impact** At least one user encountered consistent failures when attempting to generate fixes. The issue started on UTC-5 25-11-11 17:11 and was proactively discovered 22.8 hours \(TTD\) later by a staff member through our help desk [\[1\]](https://help.fluidattacks.com/agent/fluid4ttacks/fluid-attacks/tickets/details/944043000053690769) that the extension and the platform displayed an `Endpoint request timed out` message when trying to generate a fix. The problem was resolved in 2.4 hours \(TTF\), resulting in a total window of exposure of 1 day \(WOE\) [\[2\]](https://gitlab.com/fluidattacks/universe/-/issues/18852). **Cause** During an internal infrastructure update, the component responsible for generating fixes was assigned an incorrect permission. This prevented it from communicating with the API that processes fix requests, causing the system to time out instead of returning a result [\[3\]](https://gitlab.com/fluidattacks/universe/-/merge_requests/88473). **Solution** The misconfigured permission was corrected using a simpler and reliable approach that restored the expected communication between components [\[4\]](https://gitlab.com/fluidattacks/universe/-/merge_requests/88574). **Conclusion** No additional preventive actions have been established for now, as this type of failure is inherently difficult to reproduce or validate in non-production environments. A more robust monitoring mechanism for the fix service may be needed to ensure faster detection when similar failures occur. **INFRASTRUCTURE\_ERROR < IMPOSSIBLE\_TO\_TEST**