Route leak incident on January 22, 2026
ID: 14a4f6f4-7144-54b5-82d4-0c0529afacdd
STIX ID: report--14a4f6f4-7144-54b5-82d4-0c0529afacdd
Feed Name: Cloudflare Blog
On January 22, 2026, Cloudflare experienced a 25-minute IPv6 BGP route leak from its Miami data center due to an overly permissive JunOS policy change deployed via automation, which unintentionally exported internal routes to peers and providers (violating valley-free routing and constituting a mix of RFC7908 Type 3/4 leaks). The incident caused congestion on Miami–Atlanta backbone links, elevated loss and latency for some customer traffic, and discard of non-customer traffic by router filters; it was mitigated by reverting the change, pausing automation, and later restoring healthy configs. Cloudflare outlined follow-ups including patching automation, adding BGP community-based safeguards, CI/CD policy checks, improving early detection, and pursuing RFC9234 (BGP roles/OTC) and ASPA adoption to prevent future leaks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
