Cloudflare security protections can be bypassed in a surprisingly simple way

Cloudflare’s Firewall and DDoS prevention tools contain two concerning vulnerabilities that could allow threat actors to send malicious traffic their way, or use their servers to direct malicious traffic elsewhere, experts claim.

According to Certitude’s researcher Stefan Proksch, the vulnerabilities can be found in Cloudflare’s Authenticated Origin Pulls and the Allowlist Cloudflare IP addresses.