A vulnerability in Cloudflare's ACME HTTP-01 challenge validation logic allowed certain requests to the /.well-known/acme-challenge/* path to bypass WAF security features. The issue occurred when a request matched a token from a different zone, causing the request to proceed to the origin without WAF processing. Cloudflare patched the vulnerability by ensuring WAF features are only disabled when the request matches a valid challenge token for the specific hostname. No customer action is required, and no malicious exploitation has been detected.

3m read timeFrom blog.cloudflare.com
Post cover image
Table of contents
How ACME works to validate certificatesThe underlying logic flawHow we mitigated this vulnerabilityCloudflare customers are protectedMoving quickly with vulnerability transparency
583 Impressions