logo

How we mitigated a vulnerability in Cloudflare’s ACME validation logic

ID: e672e75f-976c-5f0a-bd2e-999ef65ad4f3

STIX ID: report--e672e75f-976c-5f0a-bd2e-999ef65ad4f3

Feed Name: Cloudflare Blog

Threat Score
30/100

Date Published: 2026-01-19

Date Updated: 2026-04-27

Author: Hrushikesh Deshpande

...
...

Cloudflare disclosed and patched a vulnerability in its ACME HTTP-01 challenge handling where certain requests to /.well-known/acme-challenge/* could disable WAF features and be forwarded to customer origins when they should have been blocked; the issue was reported via a bug bounty, has been fixed, and there is no evidence of abuse or required customer action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.