logo

Cloudflare misconfiguration behind recent BGP route leak

ID: 323f7542-5ec5-5bc4-8920-805fcd9d9b84

STIX ID: report--323f7542-5ec5-5bc4-8920-805fcd9d9b84

Feed Name: Bleeping Computer

Date Published: 2026-01-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cloudflare reported a 25-minute IPv6 BGP route leak on January 22 caused by a misconfigured export policy in Miami that redistributed internal routes to external neighbors, creating Type 3/4 leaks per RFC 7908 and resulting in congestion, packet loss, and about 12 Gbps of dropped traffic; the company quickly reverted the change, paused automation, and plans stronger safeguards including community-based export controls, CI/CD policy checks, improved early detection, RFC 9234 validation, and promoting RPKI ASPA adoption to prevent recurrence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.