Catalog / Cloudflare Developer Platform

WAF - WAF Release - 2026-09-22

2 days agoaddedOriginal notes

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...5f21b651N/ASSRF - Cloud,Link-Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed Ruleset...0f0313d6N/ASSRF - Block jar HTTP loopback payloadLogBlockThis is a new detection.
Cloudflare Managed Ruleset...75cd912aN/ASSRF - Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed Ruleset...a1ba83f6N/ASSTI - Jinja Dangerous Globals ChainLogBlockThis is a new detection.