Skip to main content

Vendor archive

cloudflare CVEs

Beta · best-effort

61 CVEs tagged to vendor cloudflare3 Critical, 23 High, 30 Medium, 5 Low, 0 Unrated.

CVE-2026-2836

Published Mar 5, 2026

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementa…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2835

Published Mar 5, 2026

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2833

Published Mar 5, 2026

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1229

Published Feb 24, 2026

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0933

Published Jan 20, 2026

SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13353

Published Dec 2, 2025

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-7054

Published Aug 7, 2025

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection id…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4821

Published Jun 18, 2025

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually su…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4820

Published Jun 18, 2025

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually su…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4366

Published May 22, 2025

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on ca…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4144

Published May 1, 2025

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4143

Published May 1, 2025

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3978

Published Jan 29, 2025

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0651

Published Jan 22, 2025

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1765

Published Mar 12, 2024

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quich…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1410

Published Mar 12, 2024

Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0212

Published Jan 29, 2024

The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6992

Published Jan 4, 2024

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from im…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7080

Published Dec 29, 2023

The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all n…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7079

Published Dec 29, 2023

Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7078

Published Dec 29, 2023

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to list…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6193

Published Dec 12, 2023

quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path val…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6180

Published Dec 5, 2023

The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3747

Published Sep 7, 2023

Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 61 CVEsPage 1 of 3