megachangelog
Feature2026-09-22

WAF: New SSRF and SSTI threat detections

The WAF now includes new detections for Server-Side Request Forgery attacks using non-standard IP notations and jar loopback payloads, plus defenses against Server-Side Template Injection targeting Jinja environments.

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...5f21b651N/ASSRF - Cloud,Link-Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed Ruleset...0f0313d6N/ASSRF - Block jar HTTP loopback payloadLogBlockThis is a new detection.
Cloudflare Managed Ruleset...75cd912aN/ASSRF - Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed Ruleset...a1ba83f6N/ASSTI - Jinja Dangerous Globals ChainLogBlockThis is a new detection.
wafsecurityssrfsstithreat-detection

Source: original entry ↗