CVE Tools

Cloudflare

23 CVEs tracked since 2021. Since Nov 2021, none of them reached CISA KEV.

Cloudflare CVEs per month

Nov 2021 to Dec 2023. Point at a month, or focus the strip and use the arrow keys.
Cloudflare CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-1160
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-1060
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-0860
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1250

Products

The products that kept showing up in Cloudflare's monthly top three, with their CVEs summed over those months.

  1. Warp82 months
  2. Octorpki72 months
  3. Warp Mobile Client31 month
  4. Warp Client21 month
  5. Wrangler21 month
  6. Miniflare11 month
  7. Odoh-rs11 month
  8. Tokio-boring11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cloudflare.

  1. CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 20268.8
  2. CVE-2026-12523Resource exhaustion in quiche HTTP/3 and QPACK layers7.5
  3. CVE-2026-12707Unbounded path event queue growth in quiche via peer-driven source connection ID rotation7.5
  4. CVE-2026-14440Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records6.8
  5. CVE-2026-11941Use-after-free in connection ID iterator and FFI functions5.6
  6. CVE-2026-2836Cache poisoning via insecure-by-default cache key—
  7. CVE-2026-2835HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing—
  8. CVE-2026-2833HTTP Request Smuggling via Premature Upgrade—
  9. CVE-2026-1229Incorrect calculation in CIRCL secp384r1 CombinedMult9.8
  10. CVE-2026-0933OS Command Injection in `wrangler pages deploy`9.9
  11. CVE-2025-13353gokey allows secret recovery from a seed file without the master password5.5
  12. CVE-2025-59427Cloudflare vite plugin exposes secrets over the built-in dev server—
  13. CVE-2025-7054Infinite loop triggered by connection ID retirement6.5
  14. CVE-2025-4821Incorrect congestion window growth by invalid ACK ranges7.5
  15. CVE-2025-4820Incorrect congestion window growth by optimistic ACK5.3

The record

Peak rank
#77 in Nov 2021
Busiest month shown
Nov 2021, 6 CVEs
Months with a KEV entry
0 since Nov 2021
Monthly snapshots
4 since 2021
Cloudflare's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store