502 Bad Gateway Error: What It Means and How to Fix It

Published:

14 minute read

Acar Diveroli
Written by: Acar Diveroli
A line runs from CLIENT through a dotted GATEWAY ellipse and breaks before UPSTREAM; a blue 502 arrow returns to CLIENT

You open a site and get an almost empty white page: "502 Bad Gateway" in large letters and the word "nginx" underneath. On another site the page is titled "Proxy Error" and says the proxy server received an invalid response from an upstream server. Behind Cloudflare it looks friendlier, with three icons in a row and the last one, "Host", marked "Error".

All three are the same HTTP status code, and in most cases nothing is wrong on your side. Below: what "gateway" and "upstream" mean, how to read each version of the page, what a visitor can try, how a site owner finds the cause in the logs, and what a 502 from your own proxy means.

What does 502 Bad Gateway mean?

Most websites are not one computer. The address you type usually leads to a front server: a reverse proxy such as nginx or Apache, a load balancer, or a CDN (content delivery network, a service that answers for a site from many locations) such as Cloudflare. The front server does not build the page. It passes your request to the server behind it, where the site's application runs, and relays the answer back. Forward Proxy vs Reverse Proxy explains this setup.

The HTTP standard calls the front server a gateway and the one behind it the upstream server. RFC 9110 defines 502 in one sentence: a server acting as a gateway or proxy received an invalid response from the server behind it. "Invalid" covers a refused connection, a connection that closed halfway and an answer the gateway could not read.

Is a 502 error your fault?

Almost never. Your connection delivered the request to the site's front server; the failure happened after that, between two machines that belong to the site. The exception is a VPN, a proxy or a VPN extension: it fetches pages for you, so it is a gateway too, and when it cannot get a usable answer from the site it can report a 502 of its own.

How does a 502 happen, step by step?

  1. Your browser finds the front server. DNS, the internet's address book, returns the address of the CDN or reverse proxy, not of the application.
  2. The front server accepts your request and forwards it upstream, to the application: a PHP process, a Node.js app, or one of several servers in a pool.
  3. The upstream fails. It refuses the connection because it is not running, hangs up midway, or sends something that is not valid HTTP.
  4. The gateway answers 502. If the upstream was only slow and the gateway stopped waiting, the code is usually 504 instead.
  5. Your browser shows the gateway's error page, or its own page if the gateway sent an empty one.

What does the 502 page look like, and who sent it?

The look of the page tells you which program gave up. Chrome and Edge show their own page only when the gateway sends a 502 with no page attached.

What you seeSent byUsual meaning
"502 Bad Gateway", "nginx" belownginx, the site's reverse proxyThe application behind nginx is down or crashed
"Proxy Error … received an invalid response from an upstream server", "Reason: Error reading from remote server"Apache httpdThe backend hung up or passed Apache's proxy timeout
"Error 502, Bad gateway", icons for Browser, Cloudflare and Host, "Host: Error", a Ray IDCloudflareThe site's own server failed; Cloudflare works
Error 520CloudflareThe site's server sent an empty or odd answer
Error 521CloudflareThe site's server refused the connection
Error 522CloudflareConnecting to the site's server timed out
Error 523CloudflareNo route to the site's server
Error 524CloudflareThe site's server sent nothing back in time
"This page isn't working", "HTTP ERROR 502"Chrome or EdgeAn empty 502 with no detail

Apache's "Reason" line names the exact failure. The same "Proxy Error" heading with "Error during SSL Handshake with remote server" carries status 500: Apache could not set up the encrypted connection to the backend. Cloudflare explains each of its codes in its 5xx errors guide (for 524 it waits 125 seconds by default); all of them are trouble between Cloudflare and the site's server.

What is the difference between 502, 503 and 504?

CodeNameWhat happenedWho fixes it
500Internal Server ErrorThe application itself hit an errorThe site owner
502Bad GatewayThe gateway got a broken answer, or noneThe site owner
503Service UnavailableOverload or planned maintenanceUsually time
504Gateway TimeoutThe gateway waited too longThe site owner

RFC 9110 defines 504 in the same gateway terms: "an invalid answer" versus "no answer in time". For a visitor the advice is the same for all three. For an owner, 502 points to a dead or misbehaving application, 504 to a slow one. One twist: when Apache cannot connect to its backend at all, it answers 503.

What can you do as a visitor?

  1. Wait a minute, then reload. Many 502s last only while an application restarts, for example during an update. Press F5 or the Reload button on Chrome's error page; once or twice is enough.
  2. Check whether the site is down for everyone. Open it on your phone over mobile data instead of Wi-Fi. If it fails there too, the problem is on the site's side; many services announce outages on a status page.
  3. Turn off your VPN or proxy. Switch off the VPN app, VPN extension or proxy and reload. In Chrome, extensions are under More > Extensions > Manage Extensions (Google's steps). If the page now loads, the VPN's server was the gateway that failed. Not sure whether a proxy is set? What Is a Proxy Error? shows where to look.
  4. If the site moved recently, look it up again. Rarely, your computer still holds an old address for a site that changed hosts. Restarting the computer, or clearing the DNS cache as in What Is DNS?, fetches the new one.
  5. Tell the site. Send the time, the exact address and the text on the page; on a Cloudflare page, add the Ray ID.

Clearing cookies and the cache does not help: under the HTTP standard a browser does not keep a 502 for reuse unless the server explicitly allows it.

If it is your site: what causes a 502?

The visitor sees one line; your gateway's error log holds the reason. In nginx the error_log line in nginx.conf names the file, and nginx's own Linux packages write to /var/log/nginx/error.log (error_log). Apache calls its error log the first place to look; Debian and Ubuntu keep it at /var/log/apache2/error.log, Fedora and RHEL at /var/log/httpd/error_log. Search for the minute the 502 appeared.

nginx log lineWhat it meansWhat to check
connect() failed (111: Connection refused) while connecting to upstreamNothing listens at the upstream addressIs the app running on the proxy_pass port?
connect() to unix:… failed (2: No such file or directory)The socket file in the config does not existThe socket path, e.g. after a PHP upgrade
upstream prematurely closed connection while reading response header from upstreamThe app took the request and diedThe app's own log, memory limits
upstream sent too big header while reading response header from upstreamThe headers did not fit nginx's bufferLarge cookies; proxy_buffer_size
no live upstreams while connecting to upstreamEvery server in the group is marked as failedThe upstream block
upstream timed out (110: Connection timed out)The app was too slowA 504; proxy_read_timeout

In nginx's source, a timeout becomes 504 and every other upstream failure 502. A response whose first part does not fit proxy_buffer_size counts as invalid, which is why oversized cookies end in a 502. And 11: Resource temporarily unavailable on a Unix socket means its queue is full: the application is overloaded, not stopped.

Other common causes:

  • Apache's "Error reading from remote server". The backend closed the connection or stayed silent past ProxyTimeout, which defaults to the server's Timeout (mod_proxy). Unlike nginx, Apache shows a slow backend as 502.
  • Keep-alive mismatch. If the application closes idle connections sooner than the gateway expects, a request sent on a just-closed connection fails. AWS lists this among its load balancer's 502 causes and advises a keep-alive longer than the load balancer's idle timeout.
  • A firewall blocks the CDN. Behind a CDN every visitor arrives from the CDN's addresses, and a security plugin can take them for an attack. Cloudflare reports this as 521 or 522 and publishes its ranges at cloudflare.com/ips.
  • Deploys. A release that restarts the application produces 502s until it is back; restarting one server at a time closes the gap.

Longer timeouts do not cure a crashed application, so fix the upstream first. Repeated errors also reach search: Google's crawlers slow down on server errors, and URLs that keep returning them are eventually removed from the index. A monitor that checks every minute warns you first. Run it through ISP Proxy exits in a few countries and you see whether only one CDN region fails, with checks coming from fixed addresses you can allowlist.

What does a 502 from your own proxy mean?

When a scraper, a monitoring tool or an app sends traffic through a proxy, there is a second gateway in the chain: yours. When a forward proxy cannot reach the site, many proxies answer with a 502 of their own, and the site never sees the request. The two cases look different:

  • The proxy's 502 answers the request that opens the tunnel, before any page arrives. curl prints CONNECT tunnel failed, response 502; Python's Requests raises a ProxyError with Tunnel connection failed: 502 Bad Gateway (Max Retries Exceeded With URL takes it apart).
  • The site's 502 comes through a working tunnel, with the site's own error page and headers.

What to do, in order:

  1. Open the same URL without the proxy. If it fails there too, the site is down; try later.
  2. Check the host and port in your code. A typo fails at the proxy every time.
  3. Retry a few times with growing pauses, then stop. HTTP Status Codes in Web Scraping, in its section "502, 504 and connection errors", lists which codes to retry.
  4. If the URL works without the proxy but fails through one exit, start a new session. With Residential Proxy a new session brings a new exit IP and a different route.

A 502 is a failed connection, not a block: if the site answers with 429 or a block page, slow down instead of changing addresses. And if a site starts returning 502s while your crawler runs, your traffic may be part of the load; lower the number of parallel requests.

Advanced: see who sent the 502 with one command

This part is for readers comfortable with a command line. curl ships with Windows 10, Windows 11 and macOS; in Windows PowerShell type curl.exe.

bash
curl -sSI https://example.com

-I asks only for the headers; -sS hides the progress bar but keeps error messages. To go through your proxy, add -x http://user:pass@pr.proxynet.io:8000 before the address. We ran it against a test setup on our own computer (curl 8.21.0, Windows 11). A gateway whose application was switched off:

text
HTTP/1.1 502 Bad Gateway
Content-Type: text/html
Content-Length: 112

With -x, a test proxy asked to reach a port where nothing was listening:

text
HTTP/1.1 502 Bad Gateway

curl: (7) CONNECT tunnel failed, response 502

The first line is the status. On a real site, a server: header usually names the program that answered (cloudflare, nginx, Apache). The CONNECT tunnel failed line appears only when your own proxy produced the 502.

Where you might run into a 502

Common mistakes

  • Clearing cookies and the cache again and again. The 502 is made on the server side.
  • Restarting the router or reloading every second. Your connection delivered the request, and extra reloads only add load.
  • Owners: raising timeouts to hide 502s. In nginx a 502 means the application refused, crashed or answered wrongly.
  • Owners: blocking the CDN's addresses with a firewall or security plugin.
  • Proxy users: blaming the proxy before testing the URL without it.

Decision guide

Your situationWhat to do
A "502 Bad Gateway" page, other sites workWait a minute and reload
It fails on mobile data tooThe site is down; check its status page
It loads with your VPN or proxy offPick another VPN location or check the proxy
Cloudflare page with "Host: Error"Send the Ray ID and the time to the site
Your site, nginx says "Connection refused"Start the application, check the proxy_pass port
Your site, Apache says "Error reading from remote server"Check the backend, then ProxyTimeout
Your script prints "CONNECT tunnel failed, response 502"Test without the proxy, then start a new session

Frequently asked questions

How long does a 502 Bad Gateway error last?

There is no fixed time. A restart or an update causes 502s for seconds or minutes; an application that crashed while nobody was watching can return them for hours.

Can a VPN or proxy cause a 502 error?

Yes. A VPN server or proxy fetches pages for you, so when it cannot reach a site, it can answer with a 502 itself. Turn it off and reload; if the page loads, choose another location.

What does "Proxy Error: the proxy server received an invalid response from an upstream server" mean?

It is Apache's 502 page. Apache runs in front of the site as a reverse proxy, and the application behind it hung up or did not answer in time. It is the site's proxy, not one on your computer.

Is a 502 the same as a 504?

No, but they are close: with 502 the gateway got an invalid answer, with 504 no answer in time. nginx uses 504 for timeouts, while Apache shows a slow backend as 502 too.

Does a 502 error hurt a site's Google rankings?

A short outage does little. Google's crawlers slow down on server errors, and URLs that keep returning them for a long time are eventually dropped from the index.

Why does the 502 appear only on some pages, or only sometimes?

One heavy page, such as a search, may crash the application; one server in a pool may be unhealthy; or a keep-alive mismatch breaks a random request. Compare the error log's times with the requested addresses.

Summary

A 502 Bad Gateway means the site's front server got a broken answer, or none, from the server behind it. As a visitor, wait and reload, test another network, turn off VPNs and proxies, and report the time and Ray ID if it lasts. As an owner, read the gateway's error log. As a proxy user, tell your proxy's 502 apart from the site's first. You can compare proxy types for scraping and monitoring on our proxy page.

Ask ChatGPTAsk Claude