WAF – New detections released for WAF managed rulesets

WAF – New detections released for WAF managed rulesets

This week we introduced several new detections across Cloudflare Managed Rulesets, expanding coverage for high-impact vulnerability classes such as SSRF, SQLi, SSTI, Reverse Shell attempts, and Prototype Pollution. These rules aim to improve protection against attacker-controlled payloads that exploit misconfigurations or unvalidated input in web applications.

Key Findings

New detections added for multiple exploit categories:

SSRF (Server-Side Request Forgery) — new rules targeting both local and cloud metadata abuse patterns (Beta).

SQL Injection (SQLi) — rules for common patterns, sleep/time-based injections, and string/wait function exploitation across headers and URIs.

SSTI (Server-Side Template Injection) — arithmetic-based probe detections introduced across URI, header, and body fields.

Reverse Shell and XXE payloads — enhanced heuristics for command execution and XML external entity misuse.

Prototype Pollution — new Beta rule identifying common JSON payload structures used in object prototype poisoning.

PHP Wrapper Injection and HTTP Parameter Pollution detections — to catch path traversal and multi-parameter manipulation attempts.

Anomaly Header Checks — detecting CRLF injection attempts in header names.

Impact

These updates help detect multi-vector payloads that blend SSRF + RCE or SQLi + SSTI attacks, especially in cloud-hosted applications with exposed metadata endpoints or unsafe template rendering.

Prototype Pollution and HTTP parameter pollution rules address emerging JavaScript supply-chain exploitation patterns increasingly seen in real-world incidents.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset72f0ff933fb0492eb71cda50589f2a1d N/AAnomaly:Header – name – CR, LFN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset5d0377e4435f467488614170132fab7e N/AGeneric Rules – Reverse Shell – BodyN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset54e32f7f802c4a699182e8921a027008 N/AGeneric Rules – Reverse Shell – HeaderN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset7cbda8dbafbc465d9b64a8f2958d0486 N/AGeneric Rules – Reverse Shell – URIN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetb9f3420674cf481da32333dc8e0cf7ad N/AGeneric Rules – XXE – BodyN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetad55483512f0440b81426acdbf8aab5e N/AGeneric Rules – SQLi – Common Patterns – Header URIN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset849c0618d1674f1c92ba6f9b2e466337 N/AGeneric Rules – SQLi – Sleep Function – Header URIN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset1b4db4c4bd0649c095c27c6cb686ab47 N/AGeneric Rules – SQLi – String Function – Header URIN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetfa2055b84af94ba4b925f834b0633709 N/AGeneric Rules – SQLi – WaitFor Function – Header URIN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset158177dec2504acdba1f2da201a076eb N/ASSRF – Local – BetaN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset98bfd6bb46074d5b8d1c4b39743a63ec N/ASSRF – Local – 2 – BetaN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset54e1733b10da4a599e06c6fbc2e84e2d N/ASSRF – Cloud – BetaN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetecd26d61a75e46f6a4449a06ab8af26f N/ASSRF – Cloud – 2 – BetaN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetc16f4e133c4541f293142d02e6e8dc5b N/ASSTI – Arithmetic Probe – URIN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetf4fd9904e7624666b8c49cd62550d794 N/ASSTI – Arithmetic Probe – HeaderN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset5c0875604f774c36a4f9b69c659d12a6 N/ASSTI – Arithmetic Probe – BodyN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetfae6fa37ae9249d58628e54b1a3e521e N/APHP Wrapper InjectionN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset9c02e585db34440da620eb668f76bd74 N/APHP Wrapper InjectionN/ADisabledThis is a New Detection
Cloudflare Managed Rulesetcb67fe56a84747b8b64277dc091e296d N/AHTTP parameter pollutionN/ADisabledThis is a New Detection
Cloudflare Managed Ruleset443b54d984944cd69043805ee34214ef N/APrototype Pollution – Common Payloads – BetaN/ADisabledThis is a New Detection

Source: Cloudflare



Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *