CVEs we hold for Cloudflare
Records whose assigning authority named Cloudflare as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-2836Cache poisoning via insecure-by-default cache keyCloudflare https://github.com/cloudflare/pingora CVE-2026-2835HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding MisparsingCloudflare https://github.com/cloudflare/pingora CVE-2026-2833HTTP Request Smuggling via Premature UpgradeCloudflare https://github.com/cloudflare/pingora CVE-2026-14440Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsCloudflare Universal SSL CVE-2026-12707Unbounded path event queue growth in quiche via peer-driven source connection ID rotationCloudflare quiche CVE-2026-12523Resource exhaustion in quiche HTTP/3 and QPACK layersCloudflare quiche CVE-2026-1229Incorrect calculation in CIRCL secp384r1 CombinedMultCloudflare CIRCL CVE-2026-11941Use-after-free in connection ID iterator and FFI functionsCloudflare Quiche CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 2026Cloudflare https://github.com/cloudflare/pages-action CVE-2026-0933OS Command Injection in `wrangler pages deploy`Cloudflare Wrangler CVE-2025-7054Infinite loop triggered by connection ID retirementCloudflare quiche CVE-2025-59427Cloudflare vite plugin exposes secrets over the built-in dev servercloudflare workers-sdk CVE-2025-4821Incorrect congestion window growth by invalid ACK rangesCloudflare quiche CVE-2025-4820Incorrect congestion window growth by optimistic ACKCloudflare quiche CVE-2025-13353gokey allows secret recovery from a seed file without the master passwordCloudflare gokey CVE-2025-0651File symlink abuse might lead to deleting files belonging to SYSTEM userCloudflare WARP CVE-2024-1765Unlimited resource allocation by QUIC CRYPTO frames flooding in quicheCloudflare quiche CVE-2024-1410Unbounded storage of information related to connection ID retirement, in quicheCloudflare quiche CVE-2024-0212Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)Cloudflare-WordPress CVE-2023-7080Arbitrary remote code execution within wrangler dev Workers sandboxCloudflare wrangler CVE-2023-7079Arbitrary remote file read in Wrangler dev serverCloudflare wrangler CVE-2023-7078Server-Side Request Forgery (SSRF) in MiniflareCloudflare miniflare CVE-2023-6992Memory corruption issues is Cloudflare zlib implementationCloudflare zlib CVE-2023-6193Unbounded queuing of path validation messages in cloudflare-quicheCloudflare quiche CVE-2023-6180Resource exhaustion via memory leak in tokio-boringCloudflare tokio-boring CVE-2023-4241lol-html panics on certain HTML inputsCloudflare lol-html CVE-2023-3766Invalid Slice Split Results in Server PanicCloudflare odoh-rs CVE-2023-3747Insufficient Validation on Override Codes for Always-Enabled WARP ModeCloudflare WARP Client CVE-2023-3348Directory traversal vulnerability in Cloudflare WranglerCloudflare Wrangler CVE-2023-3040Out of Bounds Access Leading to Undefined BehaviorCloudflare lua-resty-json CVE-2023-3036Out of Bounds Slice index in cfnts leads to remote panicCloudflare cfnts CVE-2023-2754Plaintext transmission of DNS requests in Windows 1.1.1.1 WARP clientCloudflare WARP CVE-2023-1862Remote access to warp-svc.exe in Cloudflare WARPCloudflare WARP Client CVE-2023-1412Local Privilege Escalation Vulnerability in WARP's MSI InstallerCloudflare WARP CVE-2023-1314Local Privilege Escalation Vulnerability in cloudflared's InstallerCloudflare cloudflared CVE-2023-0654Spoofing User's Activity Loads in WARP Mobile Client (Android)Cloudflare WARP Client CVE-2023-0652Local Privilege Escalation in Cloudflare WARP Installer (Windows)Cloudflare WARP CVE-2023-0238Injecting Activity Loads in WARP Mobile ClientCloudflare WARP Client CVE-2022-4457WARP client manifest misconfiguration leading to Task HijackingCloudflare WARP CVE-2022-4428support_uri validation missing in WARP client for WindowsCloudflare WARP CVE-2022-3616OctoRPKI crash when maximum iterations number is reachedCloudflare OctoRPKI CVE-2022-3512Lock WARP switch bypass using warp-cli 'add-trusted-ssid' commandCloudflare WARP CVE-2022-3337Lock WARP switch bypass by removing VPN profile on iOS mobile clientCloudflare WARP CVE-2022-3322Lock WARP switch bypass on WARP mobile client using iOS quick actionCloudflare WARP CVE-2022-3321Lock WARP switch feature bypass on WARP mobile client for iOSCloudflare WARP CVE-2022-3320Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint commandCloudflare WARP CVE-2022-2529Multiple DoS Attack Vectors in sflow packet handlingCloudflare goflow CVE-2022-2225Zero Trust Secure Web Gateway policies bypass using WARP client subcommandsCloudflare WARP CVE-2022-2147Unquoted Service Path in Cloudflare WARP for WindowsCloudflare WARP CVE-2022-2145Cloudlfare WARP Arbitrary File OverwriteCloudflare WARP CVE-2021-3978Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiCloudflare octorpki CVE-2021-3912OctoRPKI crashes when processing GZIP bomb returned via malicious repositoryCloudflare octorpki CVE-2021-3911Misconfigured IP address field in ROA leads to OctoRPKI crashCloudflare octorpki CVE-2021-3910NUL character in ROA causes OctoRPKI to crashCloudflare octorpki CVE-2021-3909Infinite open connection causes OctoRPKI to hang foreverCloudflare octorpki CVE-2021-3908Infinite certificate chain depth results in OctoRPKI running foreverCloudflare octorpki CVE-2021-3907Arbitrary filepath traversal via URI injectionCloudflare octorpki CVE-2021-3761OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength valuesCloudflare octorpki CVE-2020-35152Privilege escalation through unquoted service binary path on Cloudflare WARP for WindowsCloudflare WARP for Windows CVE-2020-24356Local Privilege Escalation in cloudflaredCloudflare cloudflared 62 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.