Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Cloudflare — Vulnerabilities & Security Advisories 62

Browse all 62 CVE security advisories affecting Cloudflare. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Cloudflare operates as a global content delivery network and distributed reverse proxy service, providing DDoS mitigation, web application firewall capabilities, and DNS resolution. Its infrastructure handles massive internet traffic, making it a critical component of modern web security. Historically, vulnerabilities in its software stack have frequently involved remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex configuration management or third-party dependencies. While the company maintains a robust security posture with extensive bug bounty programs, the sheer scale of its attack surface results in a significant number of recorded CVEs. Notable incidents have included configuration errors leading to temporary outages or data exposure, highlighting the challenges of maintaining security at such a vast operational scale. These events underscore the importance of rigorous internal security practices and continuous monitoring within large-scale distributed systems.

CVE ID Title CVSS Severity Published
CVE-2023-2754 Plaintext transmission of DNS requests in Windows 1.1.1.1 WARP client — WARP CWE-319 7.4 High 2023-08-03
CVE-2023-3766 Invalid Slice Split Results in Server Panic — odoh-rs CWE-120 5.9 Medium 2023-08-03
CVE-2023-3348 Directory traversal vulnerability in Cloudflare Wrangler — Wrangler CWE-22 5.7 Medium 2023-08-03
CVE-2023-1862 Remote access to warp-svc.exe in Cloudflare WARP — WARP Client CWE-284 7.3 High 2023-06-20
CVE-2023-3040 Out of Bounds Access Leading to Undefined Behavior — lua-resty-json CWE-125 3.7 Low 2023-06-14
CVE-2023-3036 Out of Bounds Slice index in cfnts leads to remote panic — cfnts CWE-119 8.6 High 2023-06-14
CVE-2023-2512 Buffer under-read in workerd — workerd CWE-125 6.5 Medium 2023-05-12
CVE-2023-1732 Improper random reading in CIRCL — CIRCL CWE-20 5.3 Medium 2023-05-10
CVE-2023-0652 Local Privilege Escalation in Cloudflare WARP Installer (Windows) — WARP CWE-59 7.0 High 2023-04-06
CVE-2023-1412 Local Privilege Escalation Vulnerability in WARP's MSI Installer — WARP CWE-59 7.0 High 2023-04-05
CVE-2023-1314 Local Privilege Escalation Vulnerability in cloudflared's Installer — cloudflared CWE-59 7.5 High 2023-03-21
CVE-2022-4428 support_uri validation missing in WARP client for Windows — WARP CWE-20 8.9 High 2023-01-11
CVE-2022-4457 WARP client manifest misconfiguration leading to Task Hijacking — WARP CWE-200 5.5 Medium 2023-01-11
CVE-2022-3320 Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command — WARP CWE-862 6.7 Medium 2022-10-28
CVE-2022-3322 Lock WARP switch bypass on WARP mobile client using iOS quick action — WARP CWE-862 6.7 Medium 2022-10-28
CVE-2022-3337 Lock WARP switch bypass by removing VPN profile on iOS mobile client — WARP CWE-862 6.7 Medium 2022-10-28
CVE-2022-3321 Lock WARP switch feature bypass on WARP mobile client for iOS — WARP CWE-862 6.7 Medium 2022-10-28
CVE-2022-3512 Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command — WARP CWE-862 6.7 Medium 2022-10-28
CVE-2022-3616 OctoRPKI crash when maximum iterations number is reached — OctoRPKI CWE-754 5.4 Medium 2022-10-28
CVE-2022-2529 Multiple DoS Attack Vectors in sflow packet handling — goflow CWE-20 7.5 High 2022-09-30
CVE-2022-2225 Zero Trust Secure Web Gateway policies bypass using WARP client subcommands — WARP CWE-284 8.1 High 2022-07-26
CVE-2022-2145 Cloudlfare WARP Arbitrary File Overwrite — WARP CWE-20 5.8 Medium 2022-06-28
CVE-2022-2147 Unquoted Service Path in Cloudflare WARP for Windows — WARP CWE-428 6.5 Medium 2022-06-23
CVE-2021-3912 OctoRPKI crashes when processing GZIP bomb returned via malicious repository — octorpki CWE-400 4.2 Medium 2021-11-11
CVE-2021-3911 Misconfigured IP address field in ROA leads to OctoRPKI crash — octorpki CWE-20 4.2 Medium 2021-11-11
CVE-2021-3910 NUL character in ROA causes OctoRPKI to crash — octorpki CWE-20 4.4 Medium 2021-11-11
CVE-2021-3909 Infinite open connection causes OctoRPKI to hang forever — octorpki CWE-400 4.4 Medium 2021-11-11
CVE-2021-3908 Infinite certificate chain depth results in OctoRPKI running forever — octorpki CWE-400 5.9 Medium 2021-11-11
CVE-2021-3907 Arbitrary filepath traversal via URI injection — octorpki CWE-20 7.4 High 2021-11-11
CVE-2021-3761 OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values — octorpki 7.5 High 2021-09-09

This page lists every published CVE security advisory associated with Cloudflare. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.