Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Cloudflare — Vulnerabilities & Security Advisories 62

Browse all 62 CVE security advisories affecting Cloudflare. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Cloudflare operates as a global content delivery network and distributed reverse proxy service, providing DDoS mitigation, web application firewall capabilities, and DNS resolution. Its infrastructure handles massive internet traffic, making it a critical component of modern web security. Historically, vulnerabilities in its software stack have frequently involved remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex configuration management or third-party dependencies. While the company maintains a robust security posture with extensive bug bounty programs, the sheer scale of its attack surface results in a significant number of recorded CVEs. Notable incidents have included configuration errors leading to temporary outages or data exposure, highlighting the challenges of maintaining security at such a vast operational scale. These events underscore the importance of rigorous internal security practices and continuous monitoring within large-scale distributed systems.

CVE ID Title CVSS Severity Published
CVE-2026-11325 cloudflare/pages-action is deprecated — migration required by September 18th, 2026 — https://github.com/cloudflare/pages-action CWE-78 8.8 High 2026-08-12
CVE-2026-12523 Resource exhaustion in quiche HTTP/3 and QPACK layers — quiche 7.5 High 2026-07-14
CVE-2026-12707 Unbounded path event queue growth in quiche via peer-driven source connection ID rotation — quiche CWE-770 7.5 High 2026-07-14
CVE-2026-14440 Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records — Universal SSL - - 2026-07-01
CVE-2026-11941 Use-after-free in connection ID iterator and FFI functions — Quiche CWE-416 5.6 Medium 2026-06-19
CVE-2026-2836 Cache poisoning via insecure-by-default cache key — https://github.com/cloudflare/pingora 6.5AI Medium AI 2026-03-04
CVE-2026-2835 HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing — https://github.com/cloudflare/pingora CWE-444 7.5AI High AI 2026-03-04
CVE-2026-2833 HTTP Request Smuggling via Premature Upgrade — https://github.com/cloudflare/pingora CWE-444 7.5AI High AI 2026-03-04
CVE-2026-1229 Incorrect calculation in CIRCL secp384r1 CombinedMult — CIRCL CWE-682 7.5AI High AI 2026-02-24
CVE-2026-0933 OS Command Injection in `wrangler pages deploy` — Wrangler CWE-20 9.8AI Critical AI 2026-01-20
CVE-2025-13353 gokey allows secret recovery from a seed file without the master password — gokey CWE-330 9.1AI Critical AI 2025-12-02
CVE-2025-59427 Cloudflare vite plugin exposes secrets over the built-in dev server — workers-sdk CWE-200 5.5 - 2025-09-19
CVE-2025-7054 Infinite loop triggered by connection ID retirement — quiche CWE-835 6.5AI Medium AI 2025-08-07
CVE-2025-4821 Incorrect congestion window growth by invalid ACK ranges — quiche CWE-770 7.5 High 2025-06-18
CVE-2025-4820 Incorrect congestion window growth by optimistic ACK — quiche CWE-770 5.3 Medium 2025-06-18
CVE-2021-3978 Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki — octorpki CWE-269 7.5 High 2025-01-29
CVE-2025-0651 File symlink abuse might lead to deleting files belonging to SYSTEM user — WARP CWE-269 7.1 - 2025-01-22
CVE-2024-1410 Unbounded storage of information related to connection ID retirement, in quiche — quiche CWE-400 3.7 Low 2024-03-12
CVE-2024-1765 Unlimited resource allocation by QUIC CRYPTO frames flooding in quiche — quiche CWE-400 5.9 Medium 2024-03-12
CVE-2024-0212 Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) — Cloudflare-WordPress CWE-284 8.1 High 2024-01-29
CVE-2023-6992 Memory corruption issues is Cloudflare zlib implementation — zlib CWE-20 4.0 Medium 2024-01-04
CVE-2023-7080 Arbitrary remote code execution within wrangler dev Workers sandbox — wrangler CWE-269 8.5 High 2023-12-29
CVE-2023-7079 Arbitrary remote file read in Wrangler dev server — wrangler CWE-287 6.4 Medium 2023-12-29
CVE-2023-7078 Server-Side Request Forgery (SSRF) in Miniflare — miniflare CWE-918 7.5 High 2023-12-29
CVE-2023-6193 Unbounded queuing of path validation messages in cloudflare-quiche — quiche CWE-400 5.3 Medium 2023-12-12
CVE-2023-6180 Resource exhaustion via memory leak in tokio-boring — tokio-boring CWE-400 5.3 Medium 2023-12-05
CVE-2023-3747 Insufficient Validation on Override Codes for Always-Enabled WARP Mode — WARP Client CWE-602 5.5 Medium 2023-09-07
CVE-2023-0654 Spoofing User's Activity Loads in WARP Mobile Client (Android) — WARP Client CWE-1021 3.9 Low 2023-08-29
CVE-2023-0238 Injecting Activity Loads in WARP Mobile Client — WARP Client CWE-200 3.9 Low 2023-08-29
CVE-2023-4241 lol-html panics on certain HTML inputs — lol-html CWE-20 7.5 High 2023-08-16

This page lists every published CVE security advisory associated with Cloudflare. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.