WAF Release - 2026-09-30
This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.
Key Findings
- CVE-2026-85706: A path traversal vulnerability affecting GitLab.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | N/A | Broken Access Control - Directory Traversal | Log | Block | This is a new detection. | |
| Cloudflare Managed Ruleset | N/A | HTTP Request Smuggling - Request Body Anomaly - Beta | Log | Block | This rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ). | |
| Cloudflare Managed Ruleset | N/A | Command Injection - Generic 8 - body - Beta | Disabled | Disabled | This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ). | |
| Cloudflare Managed Ruleset | N/A | GitLab - Path Traversal- CVE:CVE-2026-85706 | Log | Block | This is a new detection. | |
| Cloudflare Managed Ruleset | N/A | Generic - Request routing cache inconsistency | N/A | Block | This is a new detection. |