This week’s release introduces new detections for Prototype Pollution across three common vectors: URI, Body, and Header/Form.
Key Findings
- These attacks can affect both API and web applications by altering normal behavior or bypassing security controls.
Impact
Exploitation may allow attackers to change internal logic or cause unexpected behavior in applications using JavaScript or Node.js frameworks. Developers should sanitize input keys and avoid merging untrusted data structures.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 32405a50728746dd8caa057b606285e6 | N/A | Generic Rules – Prototype Pollution – URI | Log | Disabled | This is a new detection |
| Cloudflare Managed Ruleset | a7da00c63c4243d2a72456fe4f59ff26 | N/A | Generic Rules – Prototype Pollution – Body | Log | Disabled | This is a new detection |
| Cloudflare Managed Ruleset | 833078bdcfa04bb7aa7b8fb67efbeb39 | N/A | Generic Rules – Prototype Pollution – Header – Form | Log | Disabled | This is a new detection |
Source: Cloudflare
Latest Posts
- Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649]
![Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649] 2 pexels babydov 7787750](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Viva Engage: Update storyline cover photos in Teams for iOS [MC1184648]
![Viva Engage: Update storyline cover photos in Teams for iOS [MC1184648] 3 pexels magda ehlers pexels 1319584](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft 365 Copilot: Configure connected agents for Researcher and other agents [MC1184654]
![Microsoft 365 Copilot: Configure connected agents for Researcher and other agents [MC1184654] 4 pexels verma harshil 3103199](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Teams: In-app survey feedback policies will be managed by default with Microsoft 365 Cloud Policy [MC1184651]
![Microsoft Teams: In-app survey feedback policies will be managed by default with Microsoft 365 Cloud Policy [MC1184651] 5 pexels steve 845242](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649] 2 pexels babydov 7787750](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-babydov-7787750-150x150.webp)
![Viva Engage: Update storyline cover photos in Teams for iOS [MC1184648] 3 pexels magda ehlers pexels 1319584](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-magda-ehlers-pexels-1319584-150x150.webp)
![Microsoft 365 Copilot: Configure connected agents for Researcher and other agents [MC1184654] 4 pexels verma harshil 3103199](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-verma-harshil-3103199-150x150.webp)
![Microsoft Teams: In-app survey feedback policies will be managed by default with Microsoft 365 Cloud Policy [MC1184651] 5 pexels steve 845242](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-steve-845242-150x150.webp)
