Catalog / Cloudflare Developer Platform

WAF - WAF Release - 2026-09-30

11 days agosecurityaddedOriginal notes

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.

Key Findings

  • CVE-2026-85706: A path traversal vulnerability affecting GitLab.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...cb14ded8N/ABroken Access Control - Directory TraversalLogBlockThis is a new detection.
Cloudflare Managed Ruleset...0364bd7eN/AHTTP Request Smuggling - Request Body Anomaly - BetaLogBlockThis rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892).
Cloudflare Managed Ruleset...d498a69aN/ACommand Injection - Generic 8 - body - BetaDisabledDisabledThis rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2).
Cloudflare Managed Ruleset...87ae8cfcN/AGitLab - Path Traversal- CVE:CVE-2026-85706LogBlockThis is a new detection.
Cloudflare Managed Ruleset...549f7356N/AGeneric - Request routing cache inconsistencyN/ABlockThis is a new detection.