Geonode logo
Website and server errors

How to Fix a 502 Bad Gateway Error

Five checks to find which server failed, then fixes for visitors, proxy users and site owners, with retry code.

Updated

TL;DR

502 Bad Gateway means a server that passes requests on, such as your proxy, Cloudflare or a site's nginx, got an invalid response from the server behind it. Usually the site's own server failed: reload after a short wait, and leave a lasting 502 to the site owner.

How each gateway and client words a 502

The server that got the bad response writes the page, so its wording shows where to look.

WhereWhat you see
nginx (default page, server_tokens off)502 Bad Gateway nginx
Apache httpd (mod_proxy)Proxy Error The proxy server received an invalid response from an upstream server. The proxy server could not handle the request Reason: Error reading from remote server
Cloudflare, site's server failed (branded page)Bad gateway. Error code 502. The web server reported a bad gateway error.
Cloudflare itself (plain page)502 Bad Gateway cloudflare
curl via a proxy on https:// (older curl prints 56)curl: (7) CONNECT tunnel failed, response 502
Chrome (502 with an empty body)This page isn't working. example.com is currently unable to handle this request. HTTP ERROR 502
Python requests (raise_for_status)requests.exceptions.HTTPError: 502 Server Error: Bad Gateway for url: https://example.com/

Why this happens

A server in the middle could not get a proper answer from the site's server.

Often the app behind the site's nginx or Apache has crashed or is restarting. nginx keeps 504 for timeouts, so its 502 means the app refused the connection, hung up early or sent an unusable reply.

Diagnose your 502 first

The first three need only a browser; the last two take a terminal or access to the server.

  • Turn off your proxy or VPN and reload, then try mobile data; if the page loads, your proxy, VPN or network caused the 502.

  • Read the error page; an nginx, Proxy Error or Cloudflare-branded page means the site's server failed, a plain page reading cloudflare means Cloudflare did.

  • Open another site through the same proxy; if it loads, only the proxy's path to this site failed; if not, the proxy itself is failing.

  • Run curl -sS -o /dev/null -D - via the proxy; if the CONNECT response carries the 502, the proxy sent it, not the site.

  • If you run the site, find the nginx error log line for the 502; the words after 'while' name the stage that failed.

Solutions ranked by effectiveness

Each card matches one outcome of the checks, most common first.

  1. Most common fix

    Give the site time, then reload

    Applies when the 502 also shows without your proxy or VPN: the site's own server failed.

    1. Do not resubmit a payment or order; look for a confirmation email first.

    2. If it keeps failing, send the site owner the URL and the exact time.

  2. Check next

    Retry the request from a new IP

    When the site opens directly but not through your proxy, retry GET requests on a new connection with growing pauses. On a Geonode rotating port each request gets a new IP.

    curl -sS -o /dev/null -w '%{http_code}\n' \
      --retry 2 --retry-all-errors \
      -x http://USERNAME:PASSWORD@proxy.geonode.io:9000 \
      https://example.com/
  3. Site owners

    Match the nginx log line to its fix

    For a 502 from your own nginx, apply the fix for its log message and run nginx -t before reloading.

    1. connect() failed (111: Connection refused): start the app, or fix the proxy_pass address.

    2. connect() to unix:... failed (13: Permission denied): set PHP-FPM's listen.owner and listen.group to nginx's user.

    3. upstream prematurely closed connection: check the app's own log for a crash at that moment.

    4. upstream sent too big header: set proxy_buffer_size 16k and proxy_buffers 8 16k together.

Stop the 502 from coming back

Three settings for site owners, then one logging habit for scraper authors.

  1. Run the app under systemd with Restart=on-failure, so it starts again by itself after a crash.

  2. List two or more servers in the nginx upstream block; after an error on one, nginx tries the next.

  3. Log $upstream_addr and $upstream_status in your nginx log_format to see which app server each 502 involved.

  4. In scrapers, log each 502's proxy port and headers, never the password, so your provider can trace it.

Swap out a failing sessionWhen a sticky session fails to connect, release it for a new IP.
Try residential proxies

Related errors

Learn more

FAQ

One server asked another for the page on your behalf and got a broken response or none. Your browser is not at fault, though a VPN or proxy you use can be.

It is Apache httpd's 502 page: Apache, running as a reverse proxy in front of the site's app, got no usable response from it, which only the site owner can fix.

Apache's mod_proxy prints it, then a Reason line naming what failed behind Apache. "Reason: Error during SSL Handshake with remote server" means TLS to the app failed; Apache sends that page as a 500.

Most come from the site's own server. When the page is Cloudflare's plain one, its docs point to broken gzip from that server, such as a stale Content-Length, or a few seconds of traffic moving between data centers.

Older curl prints it when the proxy answers the CONNECT request for an https:// URL with 502, so no tunnel opened and nothing from the site reached curl. Newer curl says "CONNECT tunnel failed, response 502".

No such error exists. 410 means Gone, a page removed on purpose that will likely stay gone, while Bad Gateway is always status 502.

Hold one IP for hours

Sticky ports keep one residential IP for 3 minutes to 24 hours, as you choose.