logo

ACME flaw in Cloudflare allowed attackers to reach origin servers

ID: 861d1425-331d-5b1c-a9d8-d8b81aac40fc

STIX ID: report--861d1425-331d-5b1c-a9d8-d8b81aac40fc

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cloudflare fixed an ACME HTTP-01 validation flaw that permitted requests to the /.well-known/acme-challenge/ path to bypass WAF protections and reach origin servers, potentially enabling header-based attacks (SSRF, SQLi, cache key poisoning), LFI exposure, and other risks; the issue was patched on October 27, 2025 and Cloudflare reported no signs of malicious exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.