logo

Cloudflare whacks WAF bypass bug that opened side door for attackers

ID: 81ae70f1-32e9-558f-a385-59643472442e

STIX ID: report--81ae70f1-32e9-558f-a385-59643472442e

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-01-20

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cloudflare patched an ACME HTTP-01 validation logic flaw that allowed WAF protections to be disabled when a request path matched a token without verifying the hostname, potentially enabling attackers to bypass the WAF and directly access origin servers; the bug was reported by FearsOff and fixed on October 27, with no evidence of exploitation reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.