We are increasing the maximum request-payload size the WAF inspects to 1 MB across all plans. This enhancement strengthens our detection capabilities for React RCE (CVE-2025-55182) by ensuring the WAF can fully analyse React payloads up to their standard maximum size. Long term limits might change based on plans in the future.
Key Findings
React payloads commonly have a default maximum size of 1 MB. Cloudflare WAF previously inspected up to 128 KB on Enterprise plans, with even lower limits on other plans.
Impact
All WAF rules now evaluate up to 1 MB of request payload data, improving coverage and detection accuracy.
Source: Cloudflare


![Microsoft 365 Copilot: Scheduling with Copilot in classic Outlook for Windows [MC1228333] 3 pexels ir solyanaya 197121 634548](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-ir-solyanaya-197121-634548-150x150.webp)
![Expand to full event details on iPad [MC1228329] 4 teddy bear 1835598 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/teddy-bear-1835598_1920-150x150.webp)
![Prevent/Fix (Planned) - Search by Meeting ID in Call Quality Dashboard [MC1228315] 5 pexels googledeepmind 25626593](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-googledeepmind-25626593-150x150.webp)