CrowdSec AppSec Postmortem: Sonarr/Radarr False Positive
- Date: May 25, 2026
- Severity: P3
- Status: Resolved
- Impact: Sonarr and Radarr unreachable (403) for ~15-20 minutes — CrowdSec AppSec heuristic false positive, no data loss
In short
On May 25, 2026 at around 10:02 PM (local time), Sonarr and Radarr became completely inaccessible from the home IP (82.XX.XX.XX), returning 403 on every URL including /login. The service was fully operational. Initial suspicion fell on the day’s crowdsec-cf-sync refactor deployment — the real cause was a CrowdSec AppSec heuristic false positive.





