Cloudflare WAF Bypass Flaw Exposed Origins via ACME Path, Patch Deployed

1 min read
Source: Cyber Security News
Cloudflare WAF Bypass Flaw Exposed Origins via ACME Path, Patch Deployed
Photo: Cyber Security News
TL;DR Summary

Researchers disclosed a critical flaw in Cloudflare’s edge processing that allowed requests to the ACME HTTP-01 validation path (/.well-known/acme-challenge/) to bypass WAF rules and reach origin servers, potentially exposing data across common frameworks (e.g., Spring/Tomcat, Next.js, PHP). Cloudflare issued a fix on Oct 27, 2025 ensuring ACME traffic is evaluated by WAF rules again; no customer action is required and there’s no evidence of exploitation in the wild.

Share this article

Reading Insights

Total Reads

0

Unique Readers

3

Time Saved

53 min

vs 54 min read

Condensed

99%

10,67268 words

Want the full story? Read the original article

Read on Cyber Security News