WAF – WAF Release – 2025-11-10

WAF – WAF Release – 2025-11-10

This week’s release introduces new detections for Prototype Pollution across three common vectors: URI, Body, and Header/Form.

Key Findings

  • These attacks can affect both API and web applications by altering normal behavior or bypassing security controls.

Impact

Exploitation may allow attackers to change internal logic or cause unexpected behavior in applications using JavaScript or Node.js frameworks. Developers should sanitize input keys and avoid merging untrusted data structures.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset32405a50728746dd8caa057b606285e6 N/AGeneric Rules – Prototype Pollution – URILogDisabledThis is a new detection
Cloudflare Managed Ruleseta7da00c63c4243d2a72456fe4f59ff26 N/AGeneric Rules – Prototype Pollution – BodyLogDisabledThis is a new detection
Cloudflare Managed Ruleset833078bdcfa04bb7aa7b8fb67efbeb39 N/AGeneric Rules – Prototype Pollution – Header – FormLogDisabledThis is a new detection

Source: Cloudflare



Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply