Cloudflare
23 CVEs tracked since 2021. Since Nov 2021, none of them reached CISA KEV.
Cloudflare CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-11 | 6 | 0 |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | 6 | 0 |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | 6 | 0 |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | 5 | 0 |
Products
The products that kept showing up in Cloudflare's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cloudflare.
- CVE-2026-11325cloudflare/pages-action is deprecated — migration required by September 18th, 20268.8
- CVE-2026-12523Resource exhaustion in quiche HTTP/3 and QPACK layers7.5
- CVE-2026-12707Unbounded path event queue growth in quiche via peer-driven source connection ID rotation7.5
- CVE-2026-14440Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records6.8
- CVE-2026-11941Use-after-free in connection ID iterator and FFI functions5.6
- CVE-2026-2836Cache poisoning via insecure-by-default cache key—
- CVE-2026-2835HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing—
- CVE-2026-2833HTTP Request Smuggling via Premature Upgrade—
- CVE-2026-1229Incorrect calculation in CIRCL secp384r1 CombinedMult9.8
- CVE-2026-0933OS Command Injection in `wrangler pages deploy`9.9
- CVE-2025-13353gokey allows secret recovery from a seed file without the master password5.5
- CVE-2025-59427Cloudflare vite plugin exposes secrets over the built-in dev server—
- CVE-2025-7054Infinite loop triggered by connection ID retirement6.5
- CVE-2025-4821Incorrect congestion window growth by invalid ACK ranges7.5
- CVE-2025-4820Incorrect congestion window growth by optimistic ACK5.3
The record
- Peak rank
- #77 in Nov 2021
- Busiest month shown
- Nov 2021, 6 CVEs
- Months with a KEV entry
- 0 since Nov 2021
- Monthly snapshots
- 4 since 2021