ACME flaw in Cloudflare allowed attackers to reach origin servers
ID: 861d1425-331d-5b1c-a9d8-d8b81aac40fc
STIX ID: report--861d1425-331d-5b1c-a9d8-d8b81aac40fc
Feed Name: Security Affairs
Threat Score
Cloudflare fixed an ACME HTTP-01 validation flaw that permitted requests to the /.well-known/acme-challenge/ path to bypass WAF protections and reach origin servers, potentially enabling header-based attacks (SSRF, SQLi, cache key poisoning), LFI exposure, and other risks; the issue was patched on October 27, 2025 and Cloudflare reported no signs of malicious exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
