Where
-Infinity
0

Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?

First published (updated )
Social
reddit

Cloudflare quicheResource exhaustion in quiche HTTP/3 and QPACK layers

Risk 43
Severity
7.5
First published (updated )

Cloudflare quicheUnbounded path event queue growth in quiche via peer-driven source connection ID rotation

Risk 43
Severity
7.5
First published (updated )

Cloudflare Universal SSLCloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records

Risk 56
Severity
7.6
First published (updated )

Cloudflare quicheUse-after-free in connection ID iterator and FFI functions

Risk 42
Severity
5.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cloudflare Offload, AI & Optimize with Cloudflare ImagesOffload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action

Risk 57
Severity
8.8
EPSS
0.56%
First published (updated )

Nginx nginxWe’re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, inc…

Risk 33
Severity
7
First published (updated )

oss-secHTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora

Dark ReadingContent Delivery Exploit Opens Websites to Brand Hijacking

First published (updated )

Pingora PingoraCache poisoning via insecure-by-default cache key

Risk 46
Severity
8.4
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Pingora PingoraHTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing

Risk 50
Severity
9.3
EPSS
0.06%
First published (updated )

Pingora PingoraHTTP Request Smuggling via Premature Upgrade

Risk 50
Severity
9.3
EPSS
0.06%
First published (updated )

github/cloudflare/circlIncorrect calculation in CIRCL secp384r1 CombinedMult

Risk 86
Severity
9.8
First published (updated )

The RegisterCloudflare whacks WAF bypass bug that opened side door for attackers

First published (updated )

npm/wranglerOS Command Injection in `wrangler pages deploy`

Risk 59
Severity
9.9
EPSS
0.51%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterCloudflare blames Friday outage on borked fix for React2shell vuln

First published (updated )

BleepingComputerCloudflare blames today's outage on React2Shell mitigations

First published (updated )

gokey gokeygokey allows secret recovery from a seed file without the master password

Risk 66
Severity
7.1
First published (updated )

BleepingComputerClickFix malware attacks evolve with multi-OS support, video tutorials

First published (updated )

BleepingComputerPhantomCaptcha ClickFix attack targets Ukraine war relief orgs

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)

First published (updated )
Social
reddit

Cloudflare Vite pluginCloudflare vite plugin exposes secrets over the built-in dev server

Risk 18
Severity
2.9
First published (updated )

The RegisterCloudflare DDoSed itself with React useEffect hook blunder

First published (updated )

The RegisterHow big will this Drift get? Cloudflare cops to Salesloft Drift breach

First published (updated )

BleepingComputerCloudflare hit by data breach in Salesloft Drift supply chain attack

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cloudflare Image ResizingCloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook

Risk 61
Severity
9.8
EPSS
0.52%
First published (updated )

Cloudflare quicheInfinite loop triggered by connection ID retirement

Risk 47
Severity
8.7
First published (updated )

Cloudflare quicheIncorrect congestion window growth by invalid ACK ranges

Risk 43
Severity
7.5
First published (updated )

Cloudflare quicheIncorrect congestion window growth by optimistic ACK

Risk 27
Severity
5.3
First published (updated )

npm/@opennextjs/cloudflareSSRF vulnerability in opennextjs-cloudflare via /_next/image endpoint

Risk 47
Severity
7.8
EPSS
0.09%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203