AdGuard for Windows October incident report: Post Mortem

Recently, some AdGuard for Windows users have been encountering problems with their app. After releasing version 7.22, we discovered that the update caused occasional page loading issues in browsers. While the issue was quickly mitigated for Chrome, it persisted longer in Firefox, since the bug proved rare and difficult to reproduce, stemming from an unusual combination of factors that were not detected during testing.

As of this publication, we’ve released a hotfix — AdGuard for Windows v7.22.1 — that fully resolves the issue. Please make sure your app is updated to the latest version for a smooth experience. If you use AdGuard on other platforms, there’s no need to take any action, everything should be working as expected.

We sincerely apologize for the inconvenience and hope this incident does not affect your overall experience with AdGuard. This was a one-time occurrence that will not happen again. Beyond addressing the technical issue, we also reviewed our internal processes and have already implemented several improvements to prevent similar situations in the future.

Below is the timeline of events that led to the incident, after which we will provide more technical details and list the measures we are taking to avoid anything like this in the future.

Events timeline

October 2

We released AdGuard for Windows v7.22.

October 4

A user opened a GitHub issue reporting page loading problems and, eventually, a Timed out error after updating to version 7.22.

October 6

Our QA team began investigating the issue but was unable to reproduce it. The team escalated the problem to developers the same day, and internal discussions began.

October 16

As more users joined the GitHub discussion, reports and upvotes accumulated. Unfortunately, at this stage, the QA team did not follow internal escalation guidelines for issues of this level. We faced severe difficulties when trying to reproduce the bug, partly because of the inconsistent nature of the user reports. This led the team to assume that it had been introduced a couple of versions back, and therefore didn’t require a hotfix. As a result, we postponed it for the next scheduled version, and, although the task was marked P1: Critical, it was not properly escalated, and valuable time was lost.

October 30

After 24 days, the issue resurfaced internally, revealing the true extent of its impact on users. Once we successfully reproduced the problem, we were able to estimate the overall damage more accurately. Work immediately began on a hotfix (v7.22.1). However, much of the time and effort went into reliably reproducing the problem and understanding its main cause. Several hypotheses were tested and ruled out during this process.

During the investigation, we also discovered a Firefox bug related to QUIC connections, which further slowed page loading and complicated debugging. Additionally, an issue was found with the lack of QUIC connection filtering when AdGuard was running alongside AdGuard VPN in compatibility mode with Wintun disabled.

November 1

We partially identified the cause of the issue and found a way to reproduce it. A fix was implemented in DnsLibs, our DNS filtering engine, and a nightly build was released for testing.

November 5

We pinpointed the main cause — a bug in the routing loop detection component of CoreLibs, AdGuard’s filtering engine. The issue was promptly fixed, and a second nightly build was released.

November 6

Testing of the nightly builds showed that the initial fixes resolved most problems with TCP connections, but some UDP-related issues remained. To minimize user impact, we decided to roll out the fixes in two phases. First, a third nightly build addressed these additional issues, including final library fixes and updates to driver instructions. We then prepared and thoroughly tested the v7.22.1 patch, which was released the same day.

Technical details

The bug

The bug in AdGuard for Windows v7.22 caused occasional, unpredictable freezes when loading certain pages in Firefox. It did not affect Chrome users as much. The issue began after CoreLibs v1.19 introduced protection against routing loops, a mechanism designed to prevent traffic from looping back into itself.

The bug itself had two main causes. First, a programming error excluded a port from the routing loop check, which meant that some legitimate filtered connections, such as browser requests, could be blocked. This was triggered by some service requests originating from AdGuard, such as OCSP requests. After such requests, the next browser connection would be interrupted.

Second, the check was applied in the wrong place to already established connections, resulting in unnecessary connection blocks.

Why do we need protection against routing loops?

A routing loop occurs when traffic loops back to its source application. Such loops can cause slower connections and high CPU usage. Normally, these situations do not occur, but due to interactions with other software, routing loops can still happen. To prevent them, AdGuard tracks outgoing connections by their source address and terminates any that return to the same address.

Why did it only slightly affect Chrome?

Because only the connection immediately following a service one was broken, Chrome users were much less likely to notice the issue. This is because Chrome automatically attempts to perform the same network request again after a connection is reset.

Firefox users, however, were affected in a more direct way — the browser’s design does not include automatic retry attempts after any kind of network error, which made the issue more apparent for them.

What about AdGuard for Linux and Android?

The problem in question was not detected during the CLI stage with version 1.19, even though the newest functionality is always introduced in AdGuard CLI first, so that major issues can be found and fixed before integration into UI-based applications. In this case, the problem occurred only on Linux auto mode, and mostly in Firefox. As a result, very few users met these criteria, so no user reports were received.

The issue also did not appear in AdGuard for Android v4.12, which uses the same CoreLibs 1.19, because the incoming and outgoing connection addresses differed, preventing the same conditions that triggered the bug elsewhere.

The diagnosis

Diagnosing the issue was particularly difficult. AdGuard opens relatively few service connections, and repeated attempts to reproduce the problem often used cached OCSP requests, preventing the bug from appearing. Additionally, the problem affected only a single downstream connection at a time. Chrome users were mostly unaffected because the browser automatically retries failed connections, whereas Firefox users were directly impacted, as it does not attempt reconnections when a network error occurs.

While we were looking for this hard-to-find bug, we came across the fact that half of the reports had other symptoms, and the problems described began to recur on past versions of AdGuard as well. That’s how we also discovered a separate bug in Firefox for Windows affecting HTTP/3 connections.

In short, Firefox attempts HTTP/3 connections immediately when a site advertises support, even if the connection is not yet available. AdGuard currently does not filter HTTP/3 by default, so HTTP/3 is blocked for applications with HTTPS filtering enabled.

Usually browsers include an algorithm like Happy Eyeballs that allows you to choose which protocol works best, but Firefox for Windows immediately tries to establish an HTTP/3 connection when it receives information that a site has HTTP/3 (for instance, from a DNS record like HTTPS), and assigns requests to an HTTP/3 connection that is not yet established, despite the presence of a live HTTP/2 connection. If HTTP/3 is unavailable, it leads to pauses in site loading for 20–30 seconds, after which requests are "reassigned" to a live HTTP/2-connection.

A bug report regarding this behavior has been filled. As a preventive measure, AdGuard has introduced a modification of HTTPS-type DNS records to exclude the h3 ALPN parameter when HTTP/3 filtering is disabled. This hides the fact that HTTP/3 is available from the browser in cases where it would be blocked by AdGuard anyway.

The fix

The fix was applied in two phases.

The first phase corrected the connection-matching logic to properly include the port, which resolved most of the problem, though some false positives persisted due to Windows reusing ports from recently closed connections. A nightly build released on the evening of November 5 helped most users.

However, traces of the issue could still be seen in AdGuard logs. It turned out that the problem was only partially resolved — fixing the connection matching algorithm alone wasn’t enough, because Windows can reuse the port of an outgoing connection within a second after the socket is released. This caused another type of false positive, when unrelated connections with the same address and port were mistakenly identified as loops.

There were no clear new incidents (everyone reported that things were working fine), but potentially many users could still be affected. And that’s how we came to the second phase: it addressed these cases, resulting in the final hotfix, v7.22.1, which fully resolved the issue.

Prevention measures

This issue was not caught earlier primarily due to the difficulty of reproducing it under normal testing conditions, combined with insufficient attention to user feedback.

We are currently updating our QA and development processes, with a particular focus on combining stricter process monitoring, enhanced automation, and more rigorous testing and communication within teams. With that, we aim to prevent similar incidents in the future and ensure the reliability of AdGuard for all users.

Changing the QA team’s workflow

The QA team will start paying closer attention to the number of comments and upvotes on GitHub Issues. To minimize the human factor, this monitoring will not rely solely on manual review — automation will be introduced to track activity and the number of upvotes in public issues. If this approach proves effective, it can be scaled and applied to all QA teams across all AdGuard projects.

An additional briefing will be conducted based on our Triage Guidelines, and a mandatory practice will be introduced for internal issue assessment within Jira. This process will require a justification based on a structured internal Triage Guidelines, helping ensure consistency and transparency in prioritization decisions.

The team will also prepare a list of diagnostic questions for users, which will make it easier to identify and analyze filtering-related problems based on user feedback.

Finally, several new automated tests will be implemented to prevent similar issues in the future. A benchmark testing script is being developed to evaluate page filtering speed across different browsers. Once a performance baseline is defined, all subsequent releases will be measured against it. Currently, the automated tests are used only in Google Chrome, but we plan to extend them to Firefox as well. In addition, tests will be written to measure the loading speed of a defined set of “problematic” pages in these browsers. This list will be based on known problematic websites and will continue to expand, starting with those identified in the scope of this issue’s investigation — for example, discord.com.

Changing the development team’s workflow

The development teams will devote more attention to adding new tests — including integration tests — for new functionality whenever possible, in order to reduce the likelihood of errors appearing in future releases. Greater emphasis will also be placed on providing detailed technical documentation for new features and ensuring that all involved teams are properly informed about the need to test new functionality for potential issues and corner cases.

When integrating new versions of the CoreLibs into products, the teams will now wait for explicit approval from the CoreLibs team before proceeding. At the moment, this integration process is carried out somewhat “in isolation,” which increases the risk of missed issues.

Conclusion

We would like to apologize once again to all users affected by this incident and sincerely thank everyone who provided feedback and helped us navigate this challenging situation. Going forward, we will also be faster and more transparent in communicating with our users about any critical issues that could have significant impact.

喜歡這篇文章嗎?
AdGuard DNS AdGuard Mail AdGuard Wallet
AdGuard DNS AdGuard Mail AdGuard Wallet
AdGuard Windows 版主畫面
AdGuard Windows 版的防護畫面,顯示防護功能與設定。
AdGuard Windows 版的統計畫面,顯示已封鎖的廣告與追蹤器資料。
AdGuard Windows 版的應用程式管理畫面,顯示裝置上已安裝應用程式的防護管理選項
21,755 21755 使用者評論
極好的!

AdGuard Windows 版:PC 廣告阻擋器

Windows 版 AdGuard 不只是廣告封鎖程式,它是集成所有讓您享受最佳網路體驗的主要功能的多用途工具。其可封鎖廣告和危險網站,加速網頁載入速度,並且保護兒童的線上安全。
透過下載該程式,您接受授權協定的條款
Microsoft Store
透過下載該程式,您接受授權協定的條款
AdGuard for Windows 8.0 版本,14 天的試用期
AdGuard Mac 版主畫面
AdGuard Mac 版的隱身模式介面
21,755 21755 使用者評論
極好的!

AdGuard Mac 版:全系統廣告攔截器

Mac 版 AdGuard 是一款獨一無二的專為 MacOS 設計的廣告封鎖程式。除了保護使用者免受瀏覽器和應用程式裡惱人廣告的侵擾外,應用程式還能保護使用者免受追蹤、網路釣魚和詐騙。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard for Mac 2.19 版本,14 天的試用期
AdGuard Android 版主畫面
AdGuard Android 版的追蹤保護畫面
AdGuard Android 版的應用程式管理畫面,顯示裝置上已安裝應用程式的防護管理選項
AdGuard Android 版的統計畫面,顯示已封鎖的廣告與追蹤器資料。
AdGuard Android 版隱私瀏覽器主畫面
下載 AdGuard Android 版的 QR 碼
21,755 21755 使用者評論
極好的!

Android 版 AdGuard —廣告封鎖器

在所有瀏覽器、遊戲及其他應用中封鎖廣告和追蹤器。保護個人隱私,並讓您控制應用如何使用網路。通過 APK 安裝。
透過下載該程式,您接受授權協定的條款
閱讀更多
掃描下載
可以使用任何一款 QR 碼閱讀器
AdGuard for Android 4.14 版本,14 天的試用期
AdGuard iOS 版主畫面
AdGuard iOS 版的防護畫面,顯示防護功能與設定。
AdGuard iOS 版的統計畫面,顯示已封鎖的廣告與追蹤器資料。
下載 AdGuard iOS 版的 QR 碼
21,755 21755 使用者評論
極好的!

iOS 版 AdGuard —廣告封鎖器

適用於 iPhone 和 iPad 的最佳 iOS 廣告攔截器。AdGuard 可在 Safari 中消除各種廣告與追蹤器,並在 DNS 層級保護您在所有應用程式中的隱私。
透過下載該程式,您接受授權協定的條款
閱讀更多
掃描下載
可以使用任何一款 QR 碼閱讀器
AdGuard for iOS 版本 4.5
AdGuard 內容阻擋器主畫面
AdGuard 內容阻擋器的過濾器畫面
AdGuard 內容阻擋器的設定畫面
21,755 21755 使用者評論
極好的!

AdGuard 內容阻擋器

AdGuard 內容阻擋器可以全面阻止所有支援內容封鎖技術的行動瀏覽器中的廣告,目前包括 Samsung Internet 瀏覽器和 Yandex 瀏覽器。雖然其功能相比 Android 版 AdGuard 有所限制,但它完全免費、安裝簡單且封鎖高效。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard 內容阻擋器 版本 2.8
AdGuard 瀏覽器擴充功能的主畫面
AdGuard 瀏覽器擴充功能的追蹤防護畫面
21,755 21755 使用者評論
極好的!

AdGuard 瀏覽器擴充功能

AdGuard 是有效地封鎖於全部網頁上的所有類型廣告之最快的和最輕量的廣告封鎖擴充功能!為您使用的瀏覽器選擇 AdGuard,然後取得無廣告的、快速的和安全的瀏覽。
安裝
透過下載該程式,您接受授權協定的條款
安裝
透過下載該程式,您接受授權協定的條款
安裝
透過下載該程式,您接受授權協定的條款
安裝
透過下載該程式,您接受授權協定的條款
安裝
透過下載該程式,您接受授權協定的條款
閱讀更多
安裝
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard 瀏覽器擴充功能 版本 5.5
AdGuard 助理主畫面
21,755 21755 使用者評論
極好的!

AdGuard 助理

AdGuard 桌面應用的配套瀏覽器擴充套件。支援封鎖網頁特定內容、將網站新增至允許清單,並直接從瀏覽器提交報告。
AdGuard 助理 版本 1.4
21,755 21755 使用者評論
極好的!

AdGuard Home

AdGuard Home 是一款以網路為基礎的解決方案,用於封鎖廣告和追蹤器。只需在您的路由器上安裝一次,即可涵蓋家庭網路上的所有裝置——無需另外安裝客戶端軟體。這對於經常威脅您隱私的各類物聯網裝置來說尤為重要。
AdGuard Home 版本 0.107
AdGuard Pro iOS 版主畫面
AdGuard Pro iOS 版的保護畫面,顯示保護功能與設定
AdGuard Pro iOS 版的統計畫面,顯示已封鎖的廣告和追蹤器資料
21,755 21755 使用者評論
極好的!

AdGuard Pro iOS 版

AdGuard Pro iOS 版預置全部進階廣告封鎖防護功能,提供與 AdGuard iOS 版付費版完全相同的工具集。其卓越之處在於:不僅能精準封鎖 Safari 瀏覽器內的廣告,更支援自訂的 DNS 設定以精細化防護策略。該產品具備跨瀏覽器與應用的全方位廣告封鎖能力,有效防護兒童遠離不良內容,並全面保障個人資料安全。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard Pro iOS 版 版本 4.5
AdGuard Mini Mac 版主畫面
AdGuard Mini Mac 版的 Safari 保護畫面
AdGuard Mini Mac 版的建立規則畫面
21,755 21755 使用者評論
極好的!

AdGuard Mini Mac 版:Safari 廣告封鎖程式

AdGuard Mini Mac 版是一款強大的 Safari 廣告攔截程式。這款輕量級應用不僅能移除廣告、封鎖追蹤器,還能顯著提升網頁載入速度。它讓您在 Safari 中專注瀏覽、免受干擾,同時確保個人資料安全私密。
安裝
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard Mini Mac 版 版本 2.3
開啟防護狀態下的 AdGuard Android TV 版本主畫面
AdGuard Android TV 版本的廣告封鎖畫面,顯示其功能與設定
AdGuard Android TV 版本的設定畫面
AdGuard Android TV 版本的應用程式管理畫面,顯示已封鎖廣告與追蹤器的應用程式。
21,755 21755 使用者評論
極好的!

AdGuard Android TV 版

Android TV 版 AdGuard 是唯一一款能封鎖廣告、保護隱私並充當智慧電視防火墻的應用程式。取得網路威脅警告,使用安全 DNS,並受益於加密流量。有了安全性和零廣告的使用體驗,使用者就可以盡情享受最喜愛的節目了!
AdGuard Android TV 版 4.14 版本,14 天的試用期
AdGuard 吉祥物 Agnar 懷抱 Linux 的企鵝吉祥物
21,755 21755 使用者評論
極好的!

AdGuard Linux 版

AdGuard Linux 版是世界上第一個系統級廣告封鎖器。封鎖廣告和追蹤器,選擇預設過濾器或新增自己的過濾器。管理流程通過命令行介面實現。
AdGuard Linux 版 版本 1.4
21,755 21755 使用者評論
極好的!

AdGuard Temp Mail

免費的臨時電子郵件地址產生器,保持匿名性並保護個人隱私。您的主收件匣中沒有垃圾郵件!
21,755 21755 使用者評論
極好的!

AdGuard DNS

AdGuard DNS 是一種不需要安裝任何的應用程式而封鎖網際網路廣告之極簡單的方式。它易於使用,完全地免費,被輕易地於任何的裝置上設置,並向您提供封鎖廣告、計數器、惡意網站和成人內容之最少必要的功能。
21,755 21755 使用者評論
極好的!

AdGuard Mail

保護個人身份,避免垃圾郵件,並使用我們的別名和臨時電子郵件地址保護收件箱。享受我們的免費電子信箱轉發服務和適用於所有作業系統的應用程式使用體驗。
21,755 21755 使用者評論
極好的!

AdGuard Wallet

一個安全且私密的加密貨幣錢包,讓您完全掌控資產。管理多個錢包,探索上千種加密貨幣以儲存、傳送及兌換。
已開始下載 AdGuard 點擊箭頭所指示的檔案開始安裝 AdGuard。 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,拖曳 AdGuard 圖像到"應用程式"檔案夾中。感謝您選擇 AdGuard! 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,點擊"安裝"。感謝您選擇 AdGuard!
在行動裝置上安裝 AdGuard