megachangelog
Feature2026-09-15

WAF Release: New threat detections for command injection, SSRF, and version control

Cloudflare WAF introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery targeting cloud metadata, and information disclosure vulnerabilities in version control history.

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...ca453d31N/ASSRF - Cloud - 3LogBlockThis is a new detection.
Cloudflare Managed Ruleset...e540f17fN/AVersion Control - Information Disclosure - BetaLogBlockThis rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).
Cloudflare Managed Ruleset...ba458b4bN/ACommand Injection - Generic 10LogBlockThis is a new detection.
wafsecuritythreat-detectionssrfinjection

Source: original entry ↗