CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Cloudflare ACME Validation Bug Allows WAF Bypass to Origin Servers

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Cloudflare addressed a security vulnerability in its ACME validation logic that could bypass WAF rules and expose origin servers. The flaw allowed requests to the ACME HTTP-01 challenge path to disable WAF protections, potentially granting access to sensitive files. The issue was discovered in October 2025 and fixed on October 27, 2025. No evidence of exploitation was found.

Timeline

  1. 20.01.2026 13:12 1 articles · 23h ago

    Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass

    Cloudflare addressed a security vulnerability in its ACME validation logic that could bypass WAF rules and expose origin servers. The flaw allowed requests to the ACME HTTP-01 challenge path to disable WAF protections, potentially granting access to sensitive files. The issue was discovered in October 2025 and fixed on October 27, 2025. No evidence of exploitation was found.

    Show sources

Information Snippets