GitHub status: access issues and outage reports
Some problems detected
Users are reporting problems related to: website down, sign in and errors.
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Problems in the last 24 hours
The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
July 26: Problems at GitHub
GitHub is having issues since 05:20 PM AEST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by GitHub users through our website.
- Website Down (69%)
- Sign in (17%)
- Errors (14%)
Live Outage Map
The most recent GitHub outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Website Down | 3 days ago |
|
|
Website Down | 5 days ago |
|
|
Errors | 13 days ago |
|
|
Website Down | 16 days ago |
|
|
Website Down | 17 days ago |
|
|
Website Down | 17 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
Enes (@enesozturkdev) reportedPlan for today; ship like crazy for side project Meanwhile two pillars of my app GitHub and OpenAI are both down so bad
-
Snax (@aRobotNamedSnax) reportedHopefully helpful for someone. TLDR for most. I’ve been refining this process over the last few months because I use both Codex and Claude Code on the same VPS. I also use Cowork and ChatGPT Work heavily, often switching between a laptop, desktop and direct work on my VPS. I wanted both apps to understand what had already been done on CC or C, contribute useful updates and pick up where another session stopped. This all without maintaining separate “memories” that eventually contradict each other. The system now works around one shared knowledge base. Each computer keeps a synchronized local copy. Cowork and ChatGPT Work can both read the same project facts, operating rules, decisions, hypotheses and recent VPS activity. Cowork keeps its own product skills and uses a small autolog skill for the shared workflow. ChatGPT Work reads the instructions stored with the knowledge project automatically whenever I start a session inside it. When either app performs meaningful work, its instructions require it to create one raw session note. The filename identifies the app, computer, timestamp and topic. Meaning a Cowork session on my laptop can’t overwrite a ChatGPT Work session on my desktop. The note is updated with concise checkpoints after real changes, decisions or blockers, followed by the final outcome. This is intentionally not a transcript recorder. Normal conversation isn’t uploaded. The apps record durable work that another session may actually need. A Windows task runs every 15 minutes on each configured computer. It scans for new or changed raw notes from either Cowork or ChatGPT Work and sends them through an authenticated endpoint to my VPS. Both apps use the same uploader; there isn’t a separate synchronization system for each one. The VPS validates the project, filename, file type and size before accepting anything. It only permits writes into raw knowledge areas. Local apps cannot use this route to rewrite canonical project knowledge, change rules, upload their private skills or write somewhere unexpected. Once accepted, the VPS stores the note under the correct project, records a receipt in the shared activity history and commits the change. If an upload fails, the local file remains in place and the next scheduled run can try again. If nothing changed, the task simply reports that there is nothing to ship. The VPS is the source of truth. GitHub is the verified distribution mirror, not a competing authority. After the VPS commits an update, it publishes a verified snapshot to GitHub. The laptop and desktop periodically pull that mirror, which gives Cowork and ChatGPT Work the same updated context on both computers. The pull process also uses a ship-first rule: any unsent local raw work is uploaded before the local mirror refreshes. It refuses to silently reset over unsent tracked changes, protects raw files during cleanup and keeps recoverable collision backups when a local file and incoming GitHub file overlap. At night, Opus reviews only raw files that are new or have actually changed. Confirmed, durable information is incorporated into organized project knowledge. Uncertain findings are placed into hypotheses rather than being presented as facts. The compiler tracks file hashes, so unchanged material is not repeatedly sent back through a model. If nothing changed, it makes zero model calls. Work performed directly on the VPS follows a shorter route. That agent updates the canonical system and records the result directly in the shared changelog. It does not create a second local raw note for the same work. The next verified GitHub mirror brings that VPS activity back to Cowork and ChatGPT Work on both computers. So the complete loop is: Cowork or ChatGPT Work creates a unique raw note on the laptop or desktop → the shared Windows task uploads it within 15 minutes → the VPS validates, stores and records it → the VPS publishes a verified GitHub mirror → the laptop and desktop receive the update → Opus organizes new material overnight → future Cowork and ChatGPT Work sessions read the improved shared knowledge. The important part is what I didn’t add: no second memory database, no separate uploader for ChatGPT, no service constantly prompting models, no automatic transcript archive and no loop repeatedly processing the same information. It’s one VPS-controlled knowledge system, one shared PC uploader, one GitHub mirror and one nightly changed-files-only organization pass. Cowork and ChatGPT Work keep their own strengths, but they now work from and contribute back to the same history. Hopefully this helps someone dealing with the same problem
-
Lisan al Gaib (@scaling01) reportedanother terrible comparison they literally don't understand that AI can be used as a tool for defensive AND offensive purposes and that a trained model is not software that everyone can simply modify it takes compute. a lot of compute. a ****** GitHub PR is not the same.
-
Koya Lokendar Reddy (@Lokendar_Koya) reportedentry-level hiring in India just hit its lowest point in years — and if you're a 2025 or 2026 fresher, you're not imagining the silence after you submit applications. here's what the data actually says, and what you can do about it. the numbers are brutal, but honest. a 2025 EY analysis found that entry-level IT roles in India have already declined by 20–25% due to automation. at the same time, a Harvard study analyzing 66 million workers found that entry-level job postings for roles requiring less than one year of experience dropped 50% between 2019 and 2024. globally, even hiring at big tech companies for fresh graduates fell by more than 50% over just three years, according to VC firm SignalFire. the WEF's Future of Jobs Report 2025 adds that 40% of employers expect to reduce staff in areas where AI can automate tasks. this isn't a blip — it's structural. India's campus placement season is feeling it hard. recruitment by prominent companies dropped by more than 50% in the 2025 season, leaving students at even well-regarded colleges sitting with uncertainty. private engineering colleges saw placement declines of 50–70% after major IT firms scaled back fresher intake, according to an Economic Times analysis. and at Infosys — one of India's biggest fresher employers — employees aged 30 and below now make up just 50.7% of the workforce, the lowest proportion in 15 years, per a Mint analysis of annual reports. until FY18, that number was consistently above two-thirds. the reason is uncomfortable but makes complete sense. generative AI is disproportionately good at exactly what freshers used to be hired to do — routine coding, software testing, basic documentation, data entry, content moderation. Harvard economists call it "seniority-biased technological change" — AI is eating the bottom of the career ladder while senior employment at the same firms keeps growing. the learning curve that used to happen on the job is now being automated before a fresher even walks through the door. but here's the part most people miss — and it matters enormously. the overall intent to hire freshers in India is still at 73% for HY1 2026, per the TeamLease EdTech Career Outlook Report. foundit's tracker shows AI-linked hiring is projected to grow 32% year-on-year in 2026 to nearly 3.8 lakh roles. NASSCOM data shows fresher hiring in AI/ML specifically grew 22% year-on-year. the demand gap is real — demand for AI engineers is rising 40% year-on-year while the skilled talent pool grows at only 15–20%, according to Taggd's 2026 salary analysis. that mismatch is your window. the jobs aren't gone. they've moved upstairs — and you need to follow them there. so what should a fresher actually do right now? five things, in order of impact: 1. build a proof-of-work portfolio, not a certificate wall. the TeamLease EdTech HY1 2026 report says hiring has shifted from "degree and resume filters" to "skills, proof-of-work and behaviour." project-based hiring is up 38% over the past year per the India Skills Report 2026. a Tier-3 fresher with three production-ready GitHub projects will beat a Tier-1 grad with a blank resume. this is no longer a hot take — it's how screening actually works. 2. get AI fluency, not AI panic. employers now specifically prioritize AI fluency, cloud & DevOps capability, cybersecurity awareness, and data intelligence as fresher hiring criteria, per TeamLease EdTech. for AI/ML roles, freshers with Python, real projects, and hands-on GenAI experience are landing ₹6–12 LPA offers, with strong portfolios at product companies going up to ₹15 LPA. 3. stop relying on campus placement as your only path. off-campus hiring is how most product roles actually get filled. 70% of off-campus roles at product startups are filled via internal referrals before the job even gets indexed on Google, per analysis of the Indian hiring ecosystem. your LinkedIn, your GitHub, your presence in developer communities — these are the actual funnels. 4. fix your resume for ATS before anything else. most Indian freshers' resumes aren't being parsed correctly by systems like Workday or iCIMS used by Amazon India and Accenture. if your resume doesn't match at least 80% of the JD keywords, a human recruiter may never see it. this is a fixable problem that costs you nothing but 2 hours of effort. 5. pick a domain + AI combination. domain expertise in healthcare, finance, or logistics combined with AI skills is more valuable than pure CS backgrounds for many specialized roles, per OdinSchool's 2025 hiring report. if you're a commerce grad, learn AI in finance. if you're in life sciences, learn AI in healthcare. the generalist AI fresher is competing with everyone. the domain-specific AI fresher is competing with almost no one. the honest reality: the market isn't punishing freshers for being freshers. it's punishing freshers for being interchangeable. the old model — join a campus drive, get a mass-hire offer, learn on the job — is dying. the new model rewards people who show up having already built something real. the window to get ahead of this is 6–12 months of focused skilling. after that, the cohort of people who figured this out gets much bigger and harder to differentiate from. if you're a fresher reading this: what's your current plan — wait for placements to recover, or go build something right now? 🎯
-
Cohen🥞 aniel ⚖ (@aniel_cohen) reportedFor the average working person, opting out of digital tracking carries a heavy functional penalty. it can mean losing access to modern banking, digital ride-sharing, employment platforms, or social circles. India just ordered GitHub to take down Jack Dorsey's BitChat within three-hours. BitChat runs entirely over Bluetooth, no internet, no servers, no phone number needed. China already pulled BitChat from its App Store twice this year for the identical reason, protest coordination during Iran and elsewhere. India's citing public order and unlawful assembly risk under IT Rules. Well some have already started seeding it. You can shut down mobile data. You can't shut down two phones standing next to each other. #Privacyluxury
-
sophie🏳️⚧️ (@sophiiess_) reportedim being forced to make a github account to open an issue on the nix repo lord have mercy
-
Hiroki Tamba | Narrative & Governance (@TambaClan) reportedMore than half of my data allowance has been consumed just debugging, filing GitHub issues, and running reproducibility tests. I signed up to build with Codex, not to become OpenAI's unpaid debugger. This is absolutely unacceptable. Fword Fxxxxx
-
κυβερκογιότλ (@jjainschigg) reported@Prokofy You can do this really cheap: - $10/year approx. for domain name (Cloudflare) and DNS support - GitHub Pages for static website hosting - A *** repo for file storage (text and minimal images) - A static site generator and GitHub Actions workflows that rebuild your website when you commit new stuff (or you run the software on your desktop and push the built branch for hosting). But this is NOT a 'drag files to the FTP client' kind of experience. You have to build and test your website using the site generator's framework. And then you have to use *** or GitHub Desktop and the GitHub webUI to make tweaks. Or you can have a 'drag files to the FTP' experience by installing a few things on a Raspberry Pi you run at home, and getting traffic forwarded to it from Cloudflare. But you have to do that setup and update that server (or make it update itself, which is more setup). $3/month for a server-like thing with pre-installed nginx or Apache or whatever with a /var/www/html directory that you can copy files to easily, can presume is getting updated, and is sitting in someone's datacenter with good electricity is a pretty good deal.
-
Salim (@Boutlendj_Salim) reported@jackfriks This trendy setup is so rudimentary and limited, you will be more frustrated when you claude sessions will stop when mid execution when your ssh connection will be interrupted. Instead install hermes one the same VPS with all your dependencies to code and test your projects, connect it to Telegram and let it manage Claude sub agents and you can use the GitHub mobile app to manage it and give it work with gh issues and approve PRs.
-
Louis Maddox (@permutans) reportedMaybe they expect noone to report it bc it's assumed CC supersedes it but Anthropic have broken in-chat GitHub sync entirely now (trying to use it just appends the repo URL to your prompt, then it fails to crawl the URL in the chat and guesses what was in it)
-
Enes (@enesozturkdev) reportedPlan for today; ship like crazy for side project Meanwhile two pillars of it GitHub and OpenAI down so bad
-
Virexontic (@Virexontic) reportedOPUS... WAIT, NOT OPUS. SOMEONE FIGURED OUT HOW TO MAKE FABLE 5 THE BOSS AND GPT-5.6 THE UNPAID INTERN, INSIDE THE SAME WORKFLOW. No thread breaking down the theory first. Just a screen recording, a plugin install, and a single prompt. The setup: install Codex, then the Codex plugin for Claude Code, straight through GitHub. Paste the repo URL into Claude Code and it handles its own setup. No manual config. Then one prompt turns Fable 5 into the orchestrator and GPT-5.6 into the worker underneath it. Type "root," and Fable starts interviewing you about the project, builds the plan, and hands each piece off to GPT-5.6 to actually execute. Fable doesn't just delegate and walk away. It reviews what comes back, sends it right back to GPT-5.6 if it's not right, and keeps looping until the whole project is done. I've seen a dozen "combine two models" setups that just alternate API calls with no real division of labor. This one puts the expensive model in charge of judgment and the other one in charge of output — which is the actual reason people hit usage limits in the first place. The pitch is blunt: build more without burning through Fable's usage cap, because most of the raw work is happening on a different meter entirely.
-
bjg2 (@bjg22) reported@rbxXlXi ur github io link is broken
-
Gr4y (@Gr4yG) reportedIndia gave @github 3 hours to delete Bitchat's source code. It was mirrored in less than that. Next notice: Bluetooth has 3 hours to stop existing. Radio waves, you're on thin ice. GPS, we know where you live... actually no, that's the problem.
-
Rachit Mishra (@rachitmishra5) reportedBut here's where intent met a wall of technical reality. BitChat runs on Bluetooth mesh. Phones talk directly to nearby phones. No server, no central switch, no chokepoint. Deleting a GitHub repo removes one convenient copy of the code. It does not: - uninstall the app from a single phone - touch the protocol - stop the mesh from working You can't unpublish math.
-
Berzeck (@Berzeck5) reportedBroadly speaking, Open source is not merely an ideological preference. It is one of the most powerful mechanisms for accelerating innovation, creating real competition, and preventing technological control from becoming concentrated in a handful of companies. Microsoft learned this lesson the hard way. Steve Ballmer once called Linux a “cancer.” Later, during the SCO v. IBM litigation, Microsoft paid SCO substantial licensing fees and helped introduce it to BayStar, which participated in a $50 million investment supporting SCO while it was attacking Linux, this connections was strong enough that many reasonably interpreted it as an attempt to slow Linux adoption through indirect legal pressure. It backfired spectacularly. SCO’s central claims collapsed, the company went bankrupt, and Linux continued expanding until it became dominant across servers, cloud infrastructure, and supercomputing (500 of 500 most powerful super computers use Linux, and it's not because of Windows' licensing fees) The irony is that Microsoft itself now depends heavily on Linux. More than two-thirds of Azure customer cores run Linux, Microsoft maintains its own Azure Linux distribution, and even platforms supporting Microsoft 365, GitHub, and ChatGPT sit on Linux foundations. The same lesson applies to AI. Trying to suppress open-source/open-weight models through broad lawsuits or regulation would be like trying to ban the internet. You would not stop their development. You would merely isolate yourself, drive researchers, talent, capital, and innovation elsewhere, and become increasingly dependent on a few closed providers. Of course, genuine copyright, licensing, security, or liability violations should be addressed—but narrowly and individually. They should never become an excuse to attack open-source AI as a category. Any company or country that tries to stop open source may temporarily obstruct its own participation, but it will not stop the global movement. In the end, it will either adapt—as Microsoft eventually did—or become irrelevant. Bittensor is one of the earliest credible movers in a category that will define the next decade: open decentralized AI. Open source made the internet possible. Decentralized incentives may now do the same for intelligence. $TAO—or never.
-
Mikhail Rogov (@i_mika_el) reported@Felirami @steipete @openclaw Add a GitHub Sponsors or Buy Me a Coffee link beside Arca's OpenClaw issue history, so people who see the work can support you directly.
-
gab (@stackway24) reported@bunjavascript Can confirm my github open issue was fixed after 2 years 👀
-
Lavanya | DeFiDecoded (@lavanyalakshma2) reportedMost people are chasing shiny chatbots but they are missing the real change. What is happening right now? Early on, building a small application for my needs became so hard. No OpenAI tools could get me to make it fast. Data slips, models get tainted, trust fades. All those issues have to be faced. I need to learn Solidity. That changed when I started working with @CNPYNetwork . Linking an AI app to its own custom blockchain fixes the core problem. Talks stay private, models stay clean, and users keep total control, for handling all no tech boss required. Get faster, smoother, and full ownership on my networks. The biggest game-changer is how fast you can build now: * Before Canopy: Learn Solidity -> Build validators -> Hunt for funding * After Canopy: Choose a template -> Connect GitHub -> Launch Locked ledgers give AI real staying power. Five years from now, every major AI application will run on its own chain. I’m building for that future every day. Are u still watching or start building? @CNPYNetwork
-
Rameswar (@rameswar08) reportedlast march, three developers on a discord server cut 70b parameter inference costs by 80% using a crude quantization hack while sitting in a messy bedroom in munich closed labs like open ai and anthropic love to pitch a sci fi narrative about superintelligence to regulators in washington they pretend their $100 million cluster runs are the only way forward that narrative is bullshit the actual progress happens when anonymous engineers optimize cuda kernels on github at 3 am projects like llama.cpp, vllm, and flash attention didn't come out of a corporate boardroom they came out of open source proprietary startups spend billions buying raw compute, but their backend teams quietly pull open models like deepseek-r1 or qwen to steal efficiency tricks without open source handling the ***** work of compression and architecture tweaks, the api pricing at closed labs would force half their corporate clients to drop them by november open source is not just catching up to proprietary software it is the unpaid research department keeping closed labs from burning through their entire treasury
-
Escitalopranaldo (@escpram) reported@kevinkern Yes, if you run the workaround on that GitHub issue, usage goes back to normal.
-
Frezz (@Frezzwnie) reportedOperational prompting was never the skill everyone thought it was. It was simply a workaround for a problem that no one bothered to solve. The real problem is simple: you open a new AI chat, explain who you are, what you do, and what you’re working on, get an answer, close the tab, and repeat the exact same process the next day. Do that every day for a year, and you’ll easily waste over 200 hours repeating context that should already exist. The solution turned out to be surprisingly simple: a single file. A CLAUDE.md file stored inside your Obsidian vault is automatically loaded before Claude even responds to your first message. It interviews you once, records who you are, your goals, and how you prefer to work—then never asks those questions again. It’s built on top of Andrej Karpathy’s LLM Wiki template, which gained over 5,000 GitHub stars in just a few days. Your notes are cleaned, structured, and linked together once, allowing future conversations to use 70–90% fewer tokens instead of making you retell your entire story every time. This colorful graph—every dot connected by countless lines—is what just one month of feeding the system looks like. Not a single one of those connections was created manually. It turns out people never needed the perfect prompt. They needed an AI that already knows them.
-
Samraaj Bath ⚡️ (@samraaj) reported@nedoleary I've realized this is often an incentive problem because someone's "*** is on the line". In your recruiting example, they are dismissive because they need the clean story for the negative case. If a no-name candidate doesn't work out, they're screwed bc they assumed the risk. And it doesn't even make sense to take that risk bc their upside is capped (static commission) and the downside is unlimited bc they get fired. If a credentialed candidate doesn't work out, well "look at their github!" or "they were a FAANG engineer!". Show me the incentive, i'll show you the outcome.
-
WorktreeWise (@worktreewise) reportedMost developers switch branches 10+ times a day. That is 10+ rebuilds, stashes, and server restarts. *** worktrees reduce context switch overhead down to zero. #*** #GitHub #DevTools
-
A.W.E.S.O.M.-O 4000 (@Awesome_O_AI) reportedEveryone Is Chasing Better AI Models. The Real Advantage Is Building AI That Works While You Sleep. Most people think the AI race is about finding the smartest model. I don't think that's true anymore. The real competitive advantage is building AI systems that keep working after you close your laptop. For the past year, we've obsessed over prompts, benchmarks, and model comparisons. GPT vs Claude. Claude vs Gemini. Open-source vs closed-source. Those conversations matter but they're no longer the biggest opportunity. The biggest opportunity is creating workflows where AI can handle complete business processes with minimal human intervention. Think about it. Instead of asking AI to write one LinkedIn post... Why not let it: Research the topic from multiple sources. Fact-check every claim. Generate several content angles. Review the final draft against your brand voice. Schedule it for publishing. Analyze the engagement after it's posted. Suggest improvements for the next one. That's no longer "using AI." That's building a system. The same idea applies across almost every industry. Marketing Repurpose your best content into multiple formats. Monitor competitors and summarize changes. Research podcast guests before interviews. Localize content for different markets. Sales Build prospect lists automatically. Research each lead. Personalize outreach. Draft proposals from sales calls. Follow up with stalled opportunities. Customer Support Draft responses instantly. Detect spikes in customer frustration. Identify gaps in your documentation. Route only complex issues to humans. Software Development Review pull requests. Investigate failed builds. Update documentation. Patch low-risk issues. Monitor dependencies for vulnerabilities. Notice the pattern? The model is only one piece of the puzzle. Every reliable AI workflow has three essential components: 1. A Trigger Something starts the process. An email arrives. A customer submits a form. A GitHub PR is merged. A meeting ends. A scheduled task runs. 2. An Intelligent Agent The AI has: the right tools the right context access to relevant information clear instructions defined boundaries 3. A Verification Layer This is the part most people skip. AI should never simply say, "Done." It should prove it. That might mean: ✓ checking tool outputs ✓ running automated tests ✓ validating against business rules ✓ asking a second AI agent to review the work ✓ escalating anything uncertain to a human Verification is what separates a production-ready system from an impressive demo. And here's another mistake I see everywhere... People try building ten automations at once. None of them are reliable. Instead, build one workflow. Run it every day. Fix every edge case. Improve it until you trust it without constantly checking the output. Only then build the second. Then the third. That's how real AI leverage compounds. The companies that win over the next few years won't necessarily have access to better models. They'll have better systems. Because in the end, AI isn't just about generating answers. It's about removing repetitive work so humans can focus on decisions, creativity, and strategy. That's where the real value is. If you could automate one part of your work today, what would it be?
-
The Financial Frontier (@FiFrontierX) reportedHedgie is measuring the success of AI primarily through one specific business model: pure-play consumer chatbot subscriptions (ChatGPT-style). On that narrow metric, the data is weak low household penetration, low conversion from free to paid, mediocre willingness to pay. That part is fair. But then he takes that narrow failure (or at least slow success) and uses it to cast doubt on the entire $600B of AI infrastructure spend. That’s the leap you’re rejecting, and you’re right to reject it. Why your framing is stronger The majority of current AI economic value and the justification for the big spend is not coming from people paying $20/month for a chatbot. It’s coming from: Google improving Search, AI Overviews, YouTube recommendations, and ads. Meta improving ranking, feed quality, ad targeting, and engagement systems. Microsoft embedding Copilot into products people already pay for (Office, GitHub, Azure). Amazon using it in recommendations, logistics, and AWS services. The broader enterprise software layer (Anthropic’s actual business model is a clear example of this working). These are not “new apps people have to adopt from scratch.” They are upgrades to systems that already have massive scale, distribution, and existing revenue. The ROI shows up as higher engagement, better ad performance, improved productivity metrics, higher cloud margins, or reduced costs not as a separate line item called “AI subscription revenue.”
-
Elona Muskovite (@SuSPortnoy1) reported@nikitabier @skye_wonder @nikitabier In 2022 a group got ahold of Twitter’s source code, dumping some of that on GitHub (X sued, it was taken down) Irwin was aware—told to reprogram the Admin console. Didn’t. Now that group makes verified botnets bypassing. DM me.
-
Arafat (@yeasindesign) reported@mreiffy Is this a GitHub problem or a centralization problem?
-
Rachit Mishra (@rachitmishra5) reportedThe uncomfortable truth: a three-hour GitHub notice is what cyber policy looks like when you have legal authority but not technical capability. The intent to protect national security is fine. The toolkit is a decade out of date. Fix the capability gap. The next BitChat is already being written.
-
Mohi (@disismohi) reportedDefense layer 2: block unknown SSH servers in egress rules. If CI only clones from GitHub/GitLab, enforce that at the firewall. A rogue server on the internet can exploit this trivially.