{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-24T16:04:49.360Z"
  },
  "data": {
    "id": "incident_statuspage_palo-alto_l3562rk3b77j",
    "slug": "palo-alto-content-9104-pulled-out-2026-05-22",
    "title": "Content 9104 Pulled Out",
    "summary": "Content 9104 Pulled Out",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-05-22T01:30:00+00:00",
    "updatedAt": "2026-05-23T01:08:20.42+00:00",
    "resolvedAt": "2026-05-22T21:30:00+00:00",
    "provider": {
      "slug": "palo-alto",
      "name": "Palo Alto Networks"
    },
    "affectedServices": [],
    "links": {
      "html": "/incidents/palo-alto-content-9104-pulled-out-2026-05-22",
      "api": "/api/v1/incidents/palo-alto-content-9104-pulled-out-2026-05-22",
      "providerHtml": "/providers/palo-alto"
    },
    "impactSummary": "Palo Alto Networks reported a none event for the affected tracked services.",
    "source": {
      "id": "source_palo_alto_status",
      "kind": "official_api",
      "name": "Palo Alto Networks Status",
      "checkedAt": "2026-07-24T16:00:49.861+00:00",
      "officialUrl": "https://status.paloaltonetworks.com",
      "statusPageUrl": "https://status.paloaltonetworks.com"
    },
    "updates": [
      {
        "id": "update_statuspage_palo-alto_l3562rk3b77j_jsyxb00gks91",
        "status": "resolved",
        "body": "Issue Description\nOn May 21, 2026, customers reported their traffic being blocked due to TID 97011: “D-Link Router DHCP Hostname Command Injection Vulnerability”, the TID was designed to block OS Command Injection attempts within the hostname fields of DHCP requests. However, the signature included a broad command-matching filter that led to false positives across customer environments, as it incorrectly triggered on legitimate hostnames containing overlapping character strings.\nFindings and Technical Analysis\nThe D-Link Router DHCP Hostname Command Injection Vulnerability (TID 97011) is an OS command injection flaw that allows command execution attempts through the DHCP Hostname fields. This vulnerability has coverage related to CVE-2025-69542 and CVE-2025-14659, such as the DIR-895LA1 which targets D-Link devices and DIR-860LB1, respectively.\nPrevious Detection Logic\nThe initial detection logic for TID 97011 included a command-filtering string within DHCP hostname fields that lacked strict boundary delimiters\nRoot Cause \nThe false positive (FP) occurred because the signature's command-validation logic triggered against legitimate hostnames containing the targeted command string as a substring. This broad matching behavior resulted in unintended traffic disruptions for multiple customers. \nProposed Solutions & Mitigation\nWe improved the signature logic to make it more resilient against false positives. The updated signature has been released with content 9105-10068.",
        "createdAt": "2026-05-23T01:05:39.135+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}