Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

WAF Release - 2026-09-22

View as MarkdownAgent setup

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Cloud,Link-Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSRF - Block jar HTTP loopback payloadLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSRF - Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSTI - Jinja Dangerous Globals ChainLogBlockThis is a new detection.