Skip to content

az network bastion ssh/tunnel fails with "Invalid WebSocket Header" on Azure CLI 2.76+ (Python 3.13 builds) on Windows #9806

Description

Describe the bug

az network bastion ssh, az network bastion tunnel, and any other bastion extension command that establishes a WebSocket tunnel fails immediately with Exception in handling client: Invalid WebSocket Header on Windows installations of Azure CLI 2.76 and later.
The HTTP POST to /api/tokens on the Bastion host succeeds (returns 200), but the subsequent WebSocket upgrade handshake is rejected internally. The tunnel terminates before any data can be forwarded. az network bastion rdp (which downloads an .rdp file without using WebSocket tunneling) works correctly, confirming the issue is specific to the tunnel code path.

To reproduce:

On a Windows 11 machine with Azure CLI installed via MSI (2.76.0 through 2.85.0 — any version bundling Python 3.13):

Related command

az network bastion ssh --name "" --resource-group "" --target-resource-id "" --auth-type "AAD" --debug

Also happens with "ssh-key" authorization type

Errors

cli.azext_bastion.tunnel: Exception in handling client: Invalid WebSocket Header
cli.azext_bastion.tunnel: Cleaning up session

Issue script & Debug output

urllib3.connectionpool: https://bst-.bastion.azure.com:443 "POST /api/tokens HTTP/1.1" 200 None
cli.azext_bastion.tunnel: Exception in handling client: Invalid WebSocket Header
cli.azext_bastion.tunnel: Cleaning up session
urllib3.connectionpool: https://bst-.bastion.azure.com:443 "DELETE /api/tokens/ HTTP/1.1" 204 0

Expected behavior

The SSH session should open through the Bastion tunnel.

Environment Summary

OS: Windows 11 (26200)
Azure CLI: 2.76.0, 2.84.0, 2.85.0 (MSI install) — all fail
Python (bundled): 3.13.x
bastion extension: 1.3.0, 1.4.0, 1.4.1, 1.4.2, 1.4.3 — all fail
ssh extension: 2.0.7

az version
{
"azure-cli": "2.85.0",
"azure-cli-core": "2.85.0",
"azure-cli-telemetry": "1.1.0",
"extensions": {
"bastion": "1.4.3",
"ssh": "2.0.7"
}
}

Additional context

This a Linux VM running Ubuntu 24.04 pro. I have tried this on multiple computers and getting the same error. Oddly, the ability to ssh into the vm from my local terminal was working for me the first few days after I first setup this VM. After another user started accessing the VM is when it seems like it stopped working. I have also tried with another bastion instance on a Windows VM that we have in a different subscription, and I am getting the same error there as well (Invalid WebSocket Header), but I am still able to RDP into that Windows VM through my native client. I am also still able to access the Linux VM through Bastion in the Azure portal via ssh-key and Entra authorization.

Activity

added
bugThis issue requires a change to an existing behavior in the product in order to be resolved.
on Apr 21, 2026
added
questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
customer-reportedIssues that are reported by GitHub users external to the Azure organization.
on Apr 21, 2026

yonzhan commented on Apr 21, 2026

@yonzhan
Collaborator

Thank you for opening this issue, we will look into it.

microsoft-github-policy-service commented on Apr 21, 2026

@microsoft-github-policy-service
Contributor

Thanks for the feedback! We are routing this to the appropriate team for follow-up. cc aznetsuppgithub.

microsoft-github-policy-service commented on Apr 21, 2026

@microsoft-github-policy-service
Contributor

Thanks for the feedback! We are routing this to the appropriate team for follow-up. cc Isabelle Morris (@isamorris), bastionsuppgithub.

removed
Azure CLI TeamThe command of the issue is owned by Azure CLI team
questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Auto-AssignAuto assign by botNetworkNetwork - BastionService AttentionThis issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions