Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

WAF Release - 2026-09-30

View as MarkdownAgent setup

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.

Key Findings

  • CVE-2026-85706: A path traversal vulnerability affecting GitLab.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ABroken Access Control - Directory TraversalLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AHTTP Request Smuggling - Request Body Anomaly - BetaLogBlockThis rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ).
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - body - BetaDisabledDisabledThis rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ).
Cloudflare Managed RulesetN/AGitLab - Path Traversal- CVE:CVE-2026-85706LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AGeneric - Request routing cache inconsistencyN/ABlockThis is a new detection.