Alerts tab not displaying all filtered alerts properly?

129 views
Skip to first unread message

Adam Risch

unread,
Sep 17, 2026, 1:32:17 PMSep 17
to ZAP User Group
This is a problem I had noticed previously but misunderstood I think - see https://groups.google.com/g/zaproxy-users/c/Dm51Q9GwD6U .

I have some alert filters setup but when I run my scan and look at the Alerts tab, some of them don't seem to be getting filtered correctly, at least in that tab. They do seem to be getting filtered out of the reports I run at the end of my scan plan, but one of them is set to filter to "info" and it's not showing up in the report that displays the info messages either. Which I'm less concerned about than the fact that the Alerts tab makes it look like these are actual findings. 

For example, in the attached image below, the two "low" findings at the top of the image should be getting filtered, one to "info" and the "other" to "false positive", but the alerts tab displays them as low findings. You'll noticed that there's no arrow to the left of these two, they can't be expanded, and that seems to be the tipoff that that these are messages that aren't getting filtered correctly. Unless I'm misunderstanding something this seems like a bug to me.

zap_alerts.jpg




Adam Risch

unread,
Sep 17, 2026, 2:31:31 PMSep 17
to ZAP User Group
Additional info:

These are the relevant alert filters from the scan plan:

- ruleId: 10054
  ruleName: Cookie without SameSite Attribute (10054)
  newRisk: Info
  parameter: (_opensaml_.*)|(_shib.*)|(TKTID)|(_tracker_visit)
  parameterRegex: true

 - ruleId: 10096
   ruleName: Timestamp Disclosure (10096)
   newRisk: False Positive
   url: https://biolincc.nhlbi.nih.gov/studies/.+?/
   urlRegex: true

For the first alert filter above, the url/cookie which "evades" the filter so to speak varies from scan to scan, sometimes it's the "_tracker_visit" cookie, other times it's "TKID".

For the second alert filter, it always seems to be the same url, https://biolincc.nhlbi.nih.gov/studies/mds/, but I don't understand why that url isn't getting filtered just like several other similar urls, for example, https://biolincc.nhlbi.nih.gov/studies/a_treat/ gets filtered every time.

Simon Bennetts

unread,
Sep 23, 2026, 11:00:42 AMSep 23
to ZAP User Group
The fact that you cannot expand those alert entries is not relevant - that just means theres only one instance of each.
In the ZAP desktop and using a session with those alerts show,  open the relevant alert filter dialog(s) and click on the Test button.
How many alerts do they apply to?
If its 0 then chances are that your filters are wrong.
Note that you will need to escape backslashes that are part of a URL, e.g. "http:\/\/example.com\/test"

Cheers,

Simon

Adam Risch

unread,
Sep 23, 2026, 12:05:57 PMSep 23
to ZAP User Group
Hi Simon - 

See my answers below:

"The fact that you cannot expand those alert entries is not relevant - that just means there's only one instance of each."

I have other alerts with only one instance and they are expandable (for example "Cross-Domain Javscript Source File Inclusion" in the screenshot above), so that's why I mentioned it.

"How many alerts do they apply to?"

Cookie without SameSite Attribute (10054) says 8 alerts, Timestamp Disclosure says 10 alerts.

"Note that you will need to escape backslashes that are part of a URL, e.g. "http:\/\/example.com\/test""

I've run a bunch of scans and haven't needed to do that yet, which I admit puzzled me. But anyway I updated the alert filter to escape the backslashes in the URL, and I got the exact same result.

Adam Risch

unread,
Sep 24, 2026, 4:00:42 PMSep 24
to ZAP User Group
Some additional information, I run these Zap scans from a VPC on my company's internal network, when I run authenticated scans on scan sites that are internal to our network I don't see these issues with the alert filters. However, when I run passive, unauthenticated scans on public-facing websites using automated scan plans that just run Spider and/or spiderClient jobs, that's when I see this sort of thing. So far it's happened on both websites that I've tried it on, and it's not limited to the 2 alert filters I described above.

Simon Bennetts

unread,
Sep 25, 2026, 7:25:29 AMSep 25
to ZAP User Group
Thanks for the information, this will hopefully allow us to reproduce the problem.

Simon

Simon Bennetts

unread,
Sep 25, 2026, 11:33:17 AMSep 25
to ZAP User Group
We have reproduced the problem and are working on a fix.
However the fix will be in the ZAP core, so will only be available in the weeklies until the next full ZAP release.

Cheers,

Simon

Adam Risch

unread,
Sep 28, 2026, 9:05:46 AM (12 days ago) Sep 28
to ZAP User Group
Great, thanks!

Simon Bennetts

unread,
Sep 30, 2026, 12:39:26 PM (10 days ago) Sep 30
to ZAP User Group
This problem should be fixed in the latest weekly release.
If you get a chance then please have a go with it and let us know if its now OK for you.

Many thanks,

Simon

ar

unread,
Sep 30, 2026, 9:24:01 PM (9 days ago) Sep 30
to zaprox...@googlegroups.com
What to do if you suspect the filter is not working correctly:
1. Check the "Informational" branch: Expand the lowest level (blue icons) in the **Alerts** tab. The alert you redirected to "Info" should be located there.
2. Check the regular expression (Regex URL) settings: If the filter is tied to a specific URL, ensure the regular expression is constructed correctly. Errors in the regular expression or parameters are the most common reason why a filter triggers inconsistently.
3. Global vs. Contextual filter: Ensure the filter type matches the execution conditions. A **Context Alert Filter** works only when the request falls within a specific ZAP context. If you launch a scan "directly" outside of a context, you must use a **Global Alert Filter**.

ср, 30 сент. 2026 г. в 19:39, Simon Bennetts <psi...@gmail.com>:
--
ZAP by Checkmarx: https://www.zaproxy.org/
---
You received this message because you are subscribed to the Google Groups "ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/zaproxy-users/3753677f-528d-4204-b2b2-ac663416a2d1n%40googlegroups.com.

ar

unread,
Sep 30, 2026, 9:28:12 PM (9 days ago) Sep 30
to zaprox...@googlegroups.com
Чтобы фильтр корректно обрабатывал появление как _tracker_visit, так и TKID (или любых других вариаций вроде TKTID), необходимо обновить регулярное выражение (regex) в поле parameter. [1]
Прямое решение
Измените строку параметра на расширенное регулярное выражение, объединяющее все нужные варианты через оператор ИЛИ (|)
parameter: (_opensaml_.*)|(_shib.*)|(TKTID)|(TKID)|(_tracker_visit)
Check the syntax: Ensure the `parameterRegex: true` flag is retained, as it instructs OWASP ZAP to interpret the parameter value as a regular expression.
  Если вариаций названий много (например, TKID, TKTID, TK_ID), их можно объединить более компактно с помощью символа необязательного символа ? или общего шаблона, например: (TKT?ID)|(_tracker_visit)|(_opensaml_.*)|(_shib.*)
If there are many name variations (e.g., TKID, TKTID, TK_ID), they can be combined more compactly using the optional character symbol `?` or a general pattern—for example: `(TKT?ID)|(_tracker_visit)|(_opensaml_.*)|(_shib.*)`



чт, 1 окт. 2026 г. в 04:23, ar <rasti...@gmail.com>:

ar

unread,
Sep 30, 2026, 9:32:08 PM (9 days ago) Sep 30
to zaprox...@googlegroups.com
english: To ensure the filter correctly handles the presence of both `_tracker_visit` and `TKID` (or any other variations like `TKTID`), you need to update the regular expression (regex) in the `parameter` field. [1]
Direct solution
Change the parameter string to an extended regular expression that combines all the required variants using the OR operator (`|`):

`parameter: (_opensaml_.*)|(_shib.*)|(TKTID)|(TKID)|(_tracker_visit)`
Check the syntax: Ensure the `parameterRegex: true` flag is retained, as it instructs OWASP ZAP to interpret the parameter value as a regular expression.
If there are many name variations (e.g., TKID, TKTID, TK_ID), they can be combined more compactly using the optional character symbol `?` or a general pattern—for example: `(TKT?ID)|(_tracker_visit)|(_opensaml_.*)|(_shib.*)`

чт, 1 окт. 2026 г. в 04:27, ar <rasti...@gmail.com>:

Adam Risch

unread,
Oct 1, 2026, 3:30:31 PM (8 days ago) Oct 1
to ZAP User Group
Hi Simon - 

I will try and test it out next week and let you know. Thanks again!

- Adam

Adam Risch

unread,
Oct 5, 2026, 3:21:08 PM (4 days ago) Oct 5
to ZAP User Group
Hi Simon - 

So I downloaded the weekly cross platform package https://github.com/zaproxy/zaproxy/releases/download/w2026-09-30/ZAP_WEEKLY_D-2026-09-30.zip, I extracted and copied the "ZAP_D-2026-09-30" folder to  C:\Program Files\ZAP\ (which is also where the stable version is currently installed, under the "Zed Attack Proxy" folder), but when I run the zap.bat file in Windows as per the readme, the Zap program doesn't launch. Am I doing something wrong, or is there some other step I need to take to run the weekly version? The download page says the cross platform package doesn't include any installers, but it doesn't give any other instructions.

ar

unread,
Oct 5, 2026, 10:13:55 PM (4 days ago) Oct 5
to zaprox...@googlegroups.com
The issue stems from the absence of a globally installed
Java (JRE/JDK) version 17 or higher.


The stable version of ZAP (from the "Zed Attack Proxy" folder)
launches via the zap.exe file because the standard Windows
installer includes a built-in Java runtime within its folder.

The cross-platform Weekly build is distributed
as a "bare" ZIP archive without an installer or built-in Java.

Consequently, the zap.bat script attempts to locate Java on your system
(via environment variables) and, failing to find it, simply closes without an error.


How to fix this


You can launch the Weekly build in two ways:


Method 1. Use the Java from the stable version (Fastest)


Since you already have the stable version installed,
a working Java runtime is guaranteed to exist within its directory.

You can force zap.bat to use that specific path.


1. Open the zap.bat file in Notepad
(located in C:\Program Files\ZAP\ZAP_D-2026-09-30\).


2. Locate the lines at the very beginning of the file
where Java is checked or launched.


3. Add an explicit path to the stable version's Java
at the very top of the file (immediately after the @echo off line)
by defining the JAVA_HOME variable:
set "JAVA_HOME=C:\Program Files\ZAP\Zed Attack Proxy\jre"
set "PATH=%JAVA_HOME%\bin;%PATH%"


(Check the exact name of the Java folder inside "Zed Attack Proxy"—it is usually named "jre").


4. Save the file and run zap.bat. Method 2. Install Java 17+ on the system (Recommended)


If you plan to use cross-platform or weekly builds regularly,
install Java globally:


1. Download JDK 17 (or a newer version) from the official website (e.g., Eclipse Temurin by Adoptium or Oracle).


2. When installing on Windows, make sure to check the following boxes:
• Set JAVA_HOME variable


• Associate .jar files


3. Restart your computer after installation.
The zap.bat script will then launch automatically.


⚠️ Important details for running on Windows
•
Administrator privileges: The C:\Program Files\ folder is system-protected.
When running zap.bat, the program might attempt to create log or
configuration files in its own directory and crash due to insufficient permissions.
Run the Command Prompt (or zap.bat itself) as Administrator,
or move the ZAP_D-2026-09-30 folder to a user-accessible directory (e.g., C:\ZAP\).


• How to view the error:
If you launch zap.bat by double-clicking it,
the console window closes immediately upon failure.
To see the exact cause, open the standard Command Prompt (cmd),
navigate to the folder using `cd "C:\Program Files\ZAP\ZAP_D-2026-09-30"`
and run zap.bat manually.
The console will not close, allowing you to view the error message.

пн, 5 окт. 2026 г. в 22:21, 'Adam Risch' via ZAP User Group <zaprox...@googlegroups.com>:
--
ZAP by Checkmarx: https://www.zaproxy.org/
---
You received this message because you are subscribed to the Google Groups "ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.

Simon Bennetts

unread,
Oct 6, 2026, 11:05:58 AM (4 days ago) Oct 6
to ZAP User Group
You will need Java 17+ installed.
Open a command prompt and then run the zap.bat file from there - that should give you more info if it doesnt work.

Cheers,

Simon

Adam Risch

unread,
Oct 8, 2026, 10:10:59 AM (2 days ago) Oct 8
to ZAP User Group
Thanks guys, it turned out that my systems team has two versions of Java installed on my VPC (11 and 21), I guess it was defaulting to Java 11 somehow, so I added 

set "JAVA_HOME=C:\Program Files\Adoptium\jdk-21"
set "PATH=%JAVA_HOME%\bin;%PATH%

to the top of the .bat file and that worked to get Zap running. I ran a couple of passive, unauthenticated scans, and the alert filter issue does appear to be fixed.

I should mention though that one of the scan plans generates a bunch of "java.lang.OutOfMemoryError: Java heap space" errors, which it doesn't in my stable (2.17.0) Zap installation. The VPC itself doesn't come anywhere near running out of memory when this happens. Not sure if that's something to do with the way I have the weekly installation setup or not, but if you think it merits looking into I can send you the log file(s) and scan plan(s). 

Simon Bennetts

unread,
Oct 9, 2026, 4:37:28 AM (21 hours ago) Oct 9
to ZAP User Group
Thanks for the update.
We find that memory issues tend to be environment specific, and difficult to reproduce unless we've somehow introduced a significant regression.
As no one else has reported any problems, and we've not seen any in our testing, I dont think the logs from your scan will help much.

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages