Traceary

Catalog / Cloudflare Developer Platform

WAF - WAF Release - 2026-08-25

yesterdayaddedOriginal notes

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode.

Key Findings

  • Four new detections move from Log to Block: HTTP/2 Request Smuggling - Request Body Anomaly and XSS - JavaScript Event Handler Coercion across Headers, Body, and URI.

  • The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule.

  • A Generic Rules - Remote Code Execution detection is added in Block mode.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...1489d892N/AHTTP/2 Request Smuggling - Request Body AnomalyLogBlockThis is a new detection.
Cloudflare Managed Ruleset...20646260N/AXSS - JavaScript Event Handler Coercion - HeadersLogBlockThis is a new detection.
Cloudflare Managed Ruleset...d706d517N/AXSS - JavaScript Event Handler Coercion - BodyLogBlockThis is a new detection.
Cloudflare Managed Ruleset...660886c8N/AXSS - JavaScript Event Handler Coercion - URILogBlockThis is a new detection.
Cloudflare Managed Ruleset...c293b926N/AXSS, HTML Injection - Script Tag - BetaLogBlockThis rule is merged into the original rule "XSS, HTML Injection - Script Tag" (ID: ...7b58420b).
Cloudflare Managed Ruleset...2ca6cce3N/AGeneric Rules - Remote Code ExecutionN/ABlockThis is a new detection.