---
title: Application security Changelog
image: https://edgetunnel-b2h.pages.dev/cf-twitter-card.png
---

> Documentation Index  
> Fetch the complete documentation index at: https://edgetunnel-b2h.pages.dev/changelog/llms.txt  
> Use this file to discover all available pages before exploring further. 

[Skip to content](#%5Ftop) 

# Changelog

New updates and improvements at Cloudflare.

[ Subscribe to RSS ](https://edgetunnel-b2h.pages.dev/changelog/rss/index.xml) [ View RSS feeds ](https://edgetunnel-b2h.pages.dev/fundamentals/new-features/available-rss-feeds/) 

Application security

![hero image](https://edgetunnel-b2h.pages.dev/_astro/hero.CVYJHPAd_26AMqX.svg) 

Apr 14, 2025
1. ### [WAF Release - 2025-04-14](https://edgetunnel-b2h.pages.dev/changelog/post/2025-04-14-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                    | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ---------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...d6b2d36c | 100739A        | Next.js - Auth Bypass - CVE:CVE-2025-29927 - 2 | Log             | Disabled   | This is a New Detection |

Apr 09, 2025
1. ### [Cloudflare Snippets are now Generally Available](https://edgetunnel-b2h.pages.dev/changelog/post/2025-04-09-snippets-ga/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  
![Cloudflare Snippets are now GA](https://edgetunnel-b2h.pages.dev/_astro/snippets-ga.BJr3csvv_Z2q49jT.webp)  
[Cloudflare Snippets](https://edgetunnel-b2h.pages.dev/rules/snippets/) are now generally available at no extra cost across all paid plans — giving you a fast, flexible way to programmatically control HTTP traffic using lightweight JavaScript.  
You can now use Snippets to modify HTTP requests and responses with confidence, reliability, and scale. Snippets are production-ready and deeply integrated with Cloudflare Rules, making them ideal for everything from quick dynamic header rewrites to advanced routing logic.  
What's new:

  * **Snippets are now GA** – Available at no extra cost on all Pro, Business, and Enterprise plans.
  * **Ready for production** – Snippets deliver a production-grade experience built for scale.
  * **Part of the Cloudflare Rules platform** – Snippets inherit request modifications from other Cloudflare products and support sequential execution, allowing you to run multiple Snippets on the same request and apply custom modifications step by step.
  * **Trace integration** – Use [Cloudflare Trace](https://edgetunnel-b2h.pages.dev/rules/trace-request/) to see which Snippets were triggered on a request — helping you understand traffic flow and debug more effectively.  
  ![Snippets shown in Cloudflare Trace results](https://edgetunnel-b2h.pages.dev/_astro/snippets-ga-trace.WlCshaFo_1WNo07.webp)  
Learn more in the [launch blog post ↗](https://blog.cloudflare.com/snippets/).

Apr 09, 2025
1. ### [Cloudflare Secrets Store now available in Beta](https://edgetunnel-b2h.pages.dev/changelog/post/2025-04-09-secrets-store-beta/)  
[ Secrets Store ](https://edgetunnel-b2h.pages.dev/secrets-store/)[ SSL/TLS ](https://edgetunnel-b2h.pages.dev/ssl/)  
Cloudflare Secrets Store is available today in Beta. You can now store, manage, and deploy account level secrets from a secure, centralized platform to your Workers.  
![Import repo or choose template](https://edgetunnel-b2h.pages.dev/_astro/secrets-store-landing-page.BQoEWsq8_ZUrGq1.webp)  
To spin up your Cloudflare Secrets Store, simply click the new Secrets Store tab [in the dashboard ↗](http://dash.cloudflare.com/?to=/:account/secrets-store) or use this Wrangler command:  
```sh  
wrangler secrets-store store create <name> --remote  
```  
The following are supported in the Secrets Store beta:

  * Secrets Store UI & API: create your store & create, duplicate, update, scope, and delete a secret
  * Workers UI: bind a new or existing account level secret to a Worker and deploy in code
  * Wrangler: create your store & create, duplicate, update, scope, and delete a secret
  * Account Management UI & API: assign Secrets Store permissions roles & view audit logs for actions taken in Secrets Store core platform  
For instructions on how to get started, visit our [developer documentation](https://edgetunnel-b2h.pages.dev/secrets-store/).

Apr 02, 2025
1. ### [WAF Release - 2025-04-02](https://edgetunnel-b2h.pages.dev/changelog/post/2025-04-02-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                                             | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | --------------------------------------------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...622f0483 | 100732         | Sitecore - Code Injection - CVE:CVE-2025-27218                                          | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...0f101cca | 100733         | Angular-Base64-Upload - Remote Code Execution - CVE:CVE-2024-42640                      | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...1bbcd247 | 100734         | Apache Camel - Remote Code Execution - CVE:CVE-2025-29891                               | Log             | Disabled   | This is a New Detection |
| Cloudflare Managed Ruleset | ...90aea1ca | 100735         | Progress Software WhatsUp Gold - Remote Code Execution - CVE:CVE-2024-4885              | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...d9d8c5f2 | 100737         | Apache Tomcat - Remote Code Execution - CVE:CVE-2025-24813                              | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...a28a42c4 | 100659         | Common Payloads for Server-side Template Injection                                      | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...daa4b037 | 100659         | Common Payloads for Server-side Template Injection - Base64                             | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...48f6a9cf | 100642         | LDAP Injection                                                                          | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...e0713e9f | 100642         | LDAP Injection Base64                                                                   | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...1bc977d1 | 100005         | DotNetNuke - File Inclusion - CVE:CVE-2018-9126, CVE:CVE-2011-1892, CVE:CVE-2022-31474  | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...bb70a463 | 100527         | Apache Struts - CVE:CVE-2021-31805                                                      | N/A             | Block      | N/A                     |
| Cloudflare Managed Ruleset | ...0c99546a | 100702         | Command Injection - CVE:CVE-2022-24108                                                  | N/A             | Block      | N/A                     |
| Cloudflare Managed Ruleset | ...9a5581d0 | 100622C        | Ivanti - Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887, CVE:CVE-2024-22024 | N/A             | Block      | N/A                     |
| Cloudflare Managed Ruleset | ...06d0b009 | 100536C        | GraphQL Command Injection                                                               | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...1651d0c8 | 100536         | GraphQL Injection                                                                       | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...af00f61d | 100536A        | GraphQL Introspection                                                                   | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...a41e5b67 | 100536B        | GraphQL SSRF                                                                            | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...433e5b3d | 100559A        | Prototype Pollution - Common Payloads                                                   | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...4816b26f | 100559A        | Prototype Pollution - Common Payloads - Base64                                          | N/A             | Disabled   | N/A                     |
| Cloudflare Managed Ruleset | ...fcea5ed2 | 100734         | Apache Camel - Remote Code Execution - CVE:CVE-2025-29891                               | N/A             | Disabled   | N/A                     |

Mar 22, 2025
1. ### [WAF Release - 2025-03-22 - Emergency](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-22-emergency-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ------------------------------------------ | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...f472013e | 100739         | Next.js - Auth Bypass - CVE:CVE-2025-29927 | N/A             | Disabled   | This is a New Detection |

Mar 22, 2025
1. ### [New Managed WAF rule for Next.js CVE-2025-29927.](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-22-next-js-vulnerability-waf/)  
[ Workers ](https://edgetunnel-b2h.pages.dev/workers/)[ Pages ](https://edgetunnel-b2h.pages.dev/pages/)[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

**Update: Mon Mar 24th, 11PM UTC**: Next.js has made further changes to address a smaller vulnerability introduced in the patches made to its middleware handling. Users should upgrade to Next.js versions `15.2.4`, `14.2.26`, `13.5.10` or `12.3.6`. **If you are unable to immediately upgrade or are running an older version of Next.js, you can enable the WAF rule described in this changelog as a mitigation**.

**Update: Mon Mar 24th, 8PM UTC**: Next.js has now [backported the patch for this vulnerability ↗](https://github.com/advisories/GHSA-f82v-jwr5-mffw) to cover Next.js v12 and v13\. Users on those versions will need to patch to `13.5.9` and `12.3.5` (respectively) to mitigate the vulnerability.

**Update: Sat Mar 22nd, 4PM UTC**: We have changed this WAF rule to opt-in only, as sites that use auth middleware with third-party auth vendors were observing failing requests.

**We strongly recommend updating your version of Next.js (if eligible)** to the patched versions, as your app will otherwise be vulnerable to an authentication bypass attack regardless of auth provider.  
#### Enable the Managed Rule (strongly recommended)  
This rule is opt-in only for sites on the Pro plan or above in the [WAF managed ruleset](https://edgetunnel-b2h.pages.dev/waf/managed-rules/).  
To enable the rule:

  1. Head to Security > WAF > Managed rules in the Cloudflare dashboard for the zone (website) you want to protect.
  2. Click the three dots next to **Cloudflare Managed Ruleset** and choose **Edit**
  3. Scroll down and choose **Browse Rules**
  4. Search for **CVE-2025-29927** (ruleId: `34583778093748cc83ff7b38f472013e`)
  5. Change the **Status** to **Enabled** and the **Action** to **Block**. You can optionally set the rule to Log, to validate potential impact before enabling it. Log will not block requests.
  6. Click **Next**
  7. Scroll down and choose **Save**  
This will enable the WAF rule and block requests with the `x-middleware-subrequest` header regardless of Next.js version.  
#### Create a WAF rule (manual)  
For users on the Free plan, or who want to define a more specific rule, you can create a [Custom WAF rule](https://edgetunnel-b2h.pages.dev/waf/custom-rules/create-dashboard/) to block requests with the `x-middleware-subrequest` header regardless of Next.js version.  
To create a custom rule:

  1. Head to Security > WAF > Custom rules in the Cloudflare dashboard for the zone (website) you want to protect.
  2. Give the rule a name - e.g. `next-js-CVE-2025-29927`
  3. Set the matching parameters for the rule match any request where the `x-middleware-subrequest` header `exists` per the rule expression below.  
```sh  
(len(http.request.headers["x-middleware-subrequest"]) > 0)  
```

  1. Set the action to 'block'. If you want to observe the impact before blocking requests, set the action to 'log' (and edit the rule later).
  2. **Deploy** the rule.  
![Next.js CVE-2025-29927 WAF rule](https://edgetunnel-b2h.pages.dev/_astro/waf-rule-cve-2025-29927.0i0XiweZ_Z8mlyw.webp)  
#### Next.js CVE-2025-29927  
We've made a WAF (Web Application Firewall) rule available to all sites on Cloudflare to protect against the [Next.js authentication bypass vulnerability ↗](https://github.com/advisories/GHSA-f82v-jwr5-mffw) (`CVE-2025-29927`) published on March 21st, 2025.

**Note**: This rule is not enabled by default as it blocked requests across sites for specific authentication middleware.

  * This managed rule protects sites using Next.js on Workers and Pages, as well as sites using Cloudflare to protect Next.js applications hosted elsewhere.
  * This rule has been made available (but not enabled by default) to all sites as part of our [WAF Managed Ruleset](https://edgetunnel-b2h.pages.dev/waf/managed-rules/reference/cloudflare-managed-ruleset/) and blocks requests that attempt to bypass authentication in Next.js applications.
  * The vulnerability affects almost all Next.js versions, and has been fully patched in Next.js `14.2.26` and `15.2.4`. Earlier, interim releases did not fully patch this vulnerability.
  * **Users on older versions of Next.js (`11.1.4` to `13.5.6`) did not originally have a patch available**, but this the patch for this vulnerability and a subsequent additional patch have been backported to Next.js versions `12.3.6` and `13.5.10` as of Monday, March 24th. Users on Next.js v11 will need to deploy the stated workaround or enable the WAF rule.  
The managed WAF rule mitigates this by blocking _external_ user requests with the `x-middleware-subrequest` header regardless of Next.js version, but we recommend users using Next.js 14 and 15 upgrade to the patched versions of Next.js as an additional mitigation.

Mar 19, 2025
1. ### [WAF Release - 2025-03-19 - Emergency](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-19-emergency-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                    | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ------------------------------ | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...a2cafae7 | 100736         | Generic HTTP Request Smuggling | N/A             | Disabled   | This is a New Detection |

Mar 18, 2025
1. ### [New API Posture Management for API Shield](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-18-api-posture-management/)  
[ API Shield ](https://edgetunnel-b2h.pages.dev/api-shield/)  
Now, API Shield **automatically** labels your API inventory with API-specific risks so that you can track and manage risks to your APIs.  
View these risks in [Endpoint Management](https://edgetunnel-b2h.pages.dev/api-shield/management-and-monitoring/) by label:  
![A list of endpoint management labels](https://edgetunnel-b2h.pages.dev/_astro/endpoint-management-label.BDmf8Ai1_ZM5mgU.webp)  
...or in [Security Center Insights](https://edgetunnel-b2h.pages.dev/security/security-insights/):  
![An example security center insight](https://edgetunnel-b2h.pages.dev/_astro/posture-management-insight.7vB7mzGI_Z1HKoUN.webp)  
API Shield will scan for risks on your API inventory daily. Here are the new risks we're scanning for and automatically labelling:

  * **cf-risk-sensitive**: applied if the customer is subscribed to the [sensitive data detection ruleset](https://edgetunnel-b2h.pages.dev/waf/managed-rules/reference/sensitive-data-detection/) and the WAF detects sensitive data returned on an endpoint in the last seven days.
  * **cf-risk-missing-auth**: applied if the customer has configured a session ID and no successful requests to the endpoint contain the session ID.
  * **cf-risk-mixed-auth**: applied if the customer has configured a session ID and some successful requests to the endpoint contain the session ID while some lack the session ID.
  * **cf-risk-missing-schema**: added when a learned schema is available for an endpoint that has no active schema.
  * **cf-risk-error-anomaly**: added when an endpoint experiences a recent increase in response errors over the last 24 hours.
  * **cf-risk-latency-anomaly**: added when an endpoint experiences a recent increase in response latency over the last 24 hours.
  * **cf-risk-size-anomaly**: added when an endpoint experiences a spike in response body size over the last 24 hours.  
In addition, API Shield has two new 'beta' scans for **Broken Object Level Authorization (BOLA) attacks**. If you're in the beta, you will see the following two labels when API Shield suspects an endpoint is suffering from a BOLA vulnerability:

  * **cf-risk-bola-enumeration**: added when an endpoint experiences successful responses with drastic differences in the number of unique elements requested by different user sessions.
  * **cf-risk-bola-pollution**: added when an endpoint experiences successful responses where parameters are found in multiple places in the request.  
We are currently accepting more customers into our beta. Contact your account team if you are interested in BOLA attack detection for your API.  
Refer to the [blog post ↗](https://blog.cloudflare.com/cloudflare-security-posture-management/) for more information about Cloudflare's expanded posture management capabilities.

Mar 17, 2025
1. ### [WAF Release - 2025-03-17](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-17-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                                            | Previous Action | New Action | Comments                                          |
| -------------------------- | ----------- | -------------- | -------------------------------------------------------------------------------------- | --------------- | ---------- | ------------------------------------------------- |
| Cloudflare Managed Ruleset | ...e59ec18a | 100725         | Fortinet FortiManager - Remote Code Execution - CVE:CVE-2023-42791, CVE:CVE-2024-23666 | Log             | Block      |                                                   |
| Cloudflare Managed Ruleset | ...1dbf58df | 100726         | Ivanti - Remote Code Execution - CVE:CVE-2024-8190                                     | Log             | Block      |                                                   |
| Cloudflare Managed Ruleset | ...0ad61fa7 | 100727         | Cisco IOS XE - Remote Code Execution - CVE:CVE-2023-20198                              | Log             | Disabled   | Fixed action value in changelog; no rule changes. |
| Cloudflare Managed Ruleset | ...7ee56b66 | 100728         | Sitecore - Remote Code Execution - CVE:CVE-2024-46938                                  | Log             | Block      |                                                   |
| Cloudflare Managed Ruleset | ...a6752a38 | 100729         | Microsoft SharePoint - Remote Code Execution - CVE:CVE-2023-33160                      | Log             | Block      |                                                   |
| Cloudflare Managed Ruleset | ...98d47b69 | 100730         | Pentaho - Template Injection - CVE:CVE-2022-43769, CVE:CVE-2022-43939                  | Log             | Block      |                                                   |
| Cloudflare Managed Ruleset | ...69fe1e0d | 100700         | Apache SSRF vulnerability CVE-2021-40438                                               | N/A             | Block      |                                                   |

Mar 11, 2025
1. ### [WAF Release - 2025-03-11 - Emergency](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-11-emergency-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                        | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | -------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...73febb31 | 100731         | Apache Camel - Code Injection - CVE:CVE-2025-27636 | N/A             | Block      | This is a New Detection |

Mar 10, 2025
1. ### [WAF Release - 2025-03-10](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-10-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ---------------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...b2a51e3d | 100722         | Ivanti - Information Disclosure - CVE:CVE-2025-0282        | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...259073d5 | 100723         | Cisco IOS XE - Information Disclosure - CVE:CVE-2023-20198 | Log             | Block      | This is a New Detection |

Mar 07, 2025
1. ### [Updated leaked credentials database](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-07-updated-leaked-credentials-database/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
Added new records to the leaked credentials database. The record sources are: Have I Been Pwned (HIBP) database, RockYou 2024 dataset, and another third-party database.

Mar 03, 2025
1. ### [WAF Release - 2025-03-03](https://edgetunnel-b2h.pages.dev/changelog/post/2025-03-03-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                                                 | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ------------------------------------------------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...93e63099 | 100721         | Ivanti - Remote Code Execution - CVE:CVE-2024-13159, CVE:CVE-2024-13160, CVE:CVE-2024-13161 | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...cac42ce2 | 100596         | Citrix Content Collaboration ShareFile - Remote Code Execution - CVE:CVE-2023-24489         | N/A             | Block      |                         |

Feb 24, 2025
1. ### [WAF Release - 2025-02-24](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-24-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                           | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ----------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...4916911e | 100718A        | SonicWall SSLVPN 2 - Auth Bypass - CVE:CVE-2024-53704 | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...c382fdec | 100720         | Palo Alto Networks - Auth Bypass - CVE:CVE-2025-0108  | Log             | Block      | This is a New Detection |

Feb 18, 2025
1. ### [WAF Release - 2025-02-18](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-18-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                         | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | --------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...a2ffa4b8 | 100715         | FortiOS - Auth Bypass - CVE:CVE-2024-55591          | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...5a883e12 | 100716         | Ivanti - Auth Bypass - CVE:CVE-2021-44529           | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...958094d3 | 100717         | SimpleHelp - Auth Bypass - CVE:CVE-2024-57727       | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...3b66df22 | 100718         | SonicWall SSLVPN - Auth Bypass - CVE:CVE-2024-53704 | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...9184699f | 100719         | Yeti Platform - Auth Bypass - CVE:CVE-2024-46507    | Log             | Block      | This is a New Detection |

Feb 14, 2025
1. ### [Upload a certificate bundle with an RSA and ECDSA certificate per custom hostname](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-14-cert-bundling-for-custom-hostnames/)  
[ SSL/TLS ](https://edgetunnel-b2h.pages.dev/ssl/)  
Cloudflare has supported both RSA and ECDSA certificates across our platform for a number of years. Both certificates offer the same security, but ECDSA is more performant due to a smaller key size. However, RSA is more widely adopted and ensures compatibility with legacy clients. Instead of choosing between them, you may want both – that way, ECDSA is used when clients support it, but RSA is available if not.  
Now, you can upload both an RSA and ECDSA certificate on a custom hostname via the API.  
```plaintext  
curl -X POST https://api.cloudflare.com/client/v4/zones/$ZONE_ID/custom_hostnames \
    -H 'Content-Type: application/json' \
    -H "X-Auth-Email: $CLOUDFLARE_EMAIL" \
    -H "X-Auth-Key: $CLOUDFLARE_API_KEY" \
    -d '{  
    "hostname": "hostname",  
    "ssl": {  
        "custom_cert_bundle": [  
            {  
                "custom_certificate": "RSA Cert",  
                "custom_key": "RSA Key"  
            },  
            {  
                "custom_certificate": "ECDSA Cert",  
                "custom_key": "ECDSA Key"  
            }  
        ],  
        "bundle_method": "force",  
        "wildcard": false,  
        "settings": {  
            "min_tls_version": "1.0"  
        }  
    }  
}’  
```  
You can also:

  * [Upload](https://edgetunnel-b2h.pages.dev/api/resources/custom%5Fhostnames/methods/create/) an RSA or ECDSA certificate to a custom hostname with an existing ECDSA or RSA certificate, respectively.
  * [Replace](https://edgetunnel-b2h.pages.dev/api/resources/custom%5Fhostnames/subresources/certificate%5Fpack/subresources/certificates/methods/update/) the RSA or ECDSA certificate with a certificate of its same type.
  * [Delete](https://edgetunnel-b2h.pages.dev/api/resources/custom%5Fhostnames/subresources/certificate%5Fpack/subresources/certificates/methods/delete/) the RSA or ECDSA certificate (if the custom hostname has both an RSA and ECDSA uploaded).  
This feature is available for Business and Enterprise customers who have purchased custom certificates.

Feb 12, 2025
1. ### [Increased Cloudflare Rules limits](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-12-rules-upgraded-limits/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  
We have upgraded and streamlined [Cloudflare Rules](https://edgetunnel-b2h.pages.dev/rules/) limits across all plans, simplifying rule management and improving scalability for everyone.

**New limits by product:**

  * [Bulk Redirects](https://edgetunnel-b2h.pages.dev/rules/url-forwarding/bulk-redirects/)  
    * Free: **20** → **10,000** URL redirects across lists
    * Pro: **500** → **25,000** URL redirects across lists
    * Business: **500** → **50,000** URL redirects across lists
    * Enterprise: **10,000** → **1,000,000** URL redirects across lists
  * [Cloud Connector](https://edgetunnel-b2h.pages.dev/rules/cloud-connector/)  
    * Free: **5** → **10** connectors
    * Enterprise: **125** → **300** connectors
  * [Custom Errors](https://edgetunnel-b2h.pages.dev/rules/custom-errors/)  
    * Pro: **5** → **25** error assets and rules
    * Business: **20** → **50** error assets and rules
    * Enterprise: **50** → **300** error assets and rules
  * [Snippets](https://edgetunnel-b2h.pages.dev/rules/snippets/)  
    * Pro: **10** → **25** code snippets and rules
    * Business: **25** → **50** code snippets and rules
    * Enterprise: **50** → **300** code snippets and rules
  * [Cache Rules](https://edgetunnel-b2h.pages.dev/cache/how-to/cache-rules/), [Configuration Rules](https://edgetunnel-b2h.pages.dev/rules/configuration-rules/), [Compression Rules](https://edgetunnel-b2h.pages.dev/rules/compression-rules/), [Origin Rules](https://edgetunnel-b2h.pages.dev/rules/origin-rules/), [Single Redirects](https://edgetunnel-b2h.pages.dev/rules/url-forwarding/single-redirects/), and [Transform Rules](https://edgetunnel-b2h.pages.dev/rules/transform/)  
    * Enterprise: **125** → **300** rules  
Gradual rollout  
Limits are updated gradually. Some customers may still see previous limits until the rollout is fully completed in the first half of 2025.

Feb 11, 2025
1. ### [Custom Errors (beta): Stored Assets & Account-level Rules](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-11-custom-errors-beta/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  
We're introducing [Custom Errors](https://edgetunnel-b2h.pages.dev/rules/custom-errors/) (beta), which builds on our existing Custom Error Responses feature with new asset storage capabilities.  
This update allows you to store externally hosted error pages on Cloudflare and reference them in custom error rules, eliminating the need to supply inline content.  
This brings the following new capabilities:

  * **Custom error assets** – Fetch and store external error pages at the edge for use in error responses.
  * **Account-Level custom errors** – Define error handling rules and assets at the account level for consistency across multiple zones. Zone-level rules take precedence over account-level ones, and assets are not shared between levels.  
You can use Cloudflare API to upload your existing assets for use with Custom Errors:  
```bash  
curl "https://api.cloudflare.com/client/v4/zones/{zone_id}/custom_pages/assets" \
--header "Authorization: Bearer <API_TOKEN>" \
--header 'Content-Type: application/json' \
--data '{  
  "name": "maintenance",  
  "description": "Maintenance template page",  
  "url": "https://example.com/"  
}'  
```  
You can then reference the stored asset in a Custom Error rule:  
```bash  
curl --request PUT \  
"https://api.cloudflare.com/client/v4/zones/{zone_id}/rulesets/phases/http_custom_errors/entrypoint" \
--header "Authorization: Bearer <API_TOKEN>" \
--header 'Content-Type: application/json' \
--data '{  
  "rules": [  
    {  
      "action": "serve_error",  
      "action_parameters": {  
        "asset_name": "maintenance",  
        "content_type": "text/html",  
        "status_code": 503  
      },  
      "enabled": true,  
      "expression": "http.request.uri.path contains \"error\""  
    }  
  ]  
}'  
```

Feb 11, 2025
1. ### [WAF Release - 2025-02-11](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-11-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                               | Previous Action | New Action | Comments                |
| -------------------------- | ----------- | -------------- | ------------------------------------------------------------------------- | --------------- | ---------- | ----------------------- |
| Cloudflare Managed Ruleset | ...483b4c26 | 100708         | Aviatrix Network - Remote Code Execution - CVE:CVE-2024-50603             | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...7e924ca3 | 100709         | Next.js - Remote Code Execution - CVE:CVE-2024-46982                      | Log             | Disabled   | This is a New Detection |
| Cloudflare Managed Ruleset | ...83a7d8ff | 100710         | Progress Software WhatsUp Gold - Directory Traversal - CVE:CVE-2024-12105 | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...baa8eb34 | 100711         | WordPress - Remote Code Execution - CVE:CVE-2024-56064                    | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...87f5d34e | 100712         | WordPress - Remote Code Execution - CVE:CVE-2024-9047                     | Log             | Block      | This is a New Detection |
| Cloudflare Managed Ruleset | ...bf72cf8a | 100713         | FortiOS - Auth Bypass - CVE:CVE-2022-40684                                | Log             | Block      | This is a New Detection |

Feb 04, 2025
1. ### [Updated leaked credentials database](https://edgetunnel-b2h.pages.dev/changelog/post/2025-02-04-updated-leaked-credentials-database/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  
Added new records to the leaked credentials database from a third-party database.

Jan 29, 2025
1. ### [New Snippets Code Editor](https://edgetunnel-b2h.pages.dev/changelog/post/2025-01-29-snippets-code-editor/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  
The new [Snippets](https://edgetunnel-b2h.pages.dev/rules/snippets/) code editor lets you edit Snippet code and rule in one place, making it easier to test and deploy changes without switching between pages.  
![New Snippets code editor](https://edgetunnel-b2h.pages.dev/_astro/snippets-new-editor.CaoIu2_-_Z2rsmyM.webp)  
What’s new:

  * **Single-page editing for code and rule** – No need to jump between screens.
  * **Auto-complete & syntax highlighting** – Get suggestions and avoid mistakes.
  * **Code formatting & refactoring** – Write cleaner, more readable code.  
Try it now in [Rules > Snippets ↗](https://dash.cloudflare.com/?to=/:account/:zone/rules/snippets).

Jan 21, 2025
1. ### [WAF Release - 2025-01-21](https://edgetunnel-b2h.pages.dev/changelog/post/2025-01-21-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                  | Previous Action | New Action | Comments                         |
| -------------------------- | ----------- | -------------- | ---------------------------- | --------------- | ---------- | -------------------------------- |
| Cloudflare Managed Ruleset | ...b090ba9a | 100303         | Command Injection - Nslookup | Log             | Block      | This was released as ...b8d152f4 |
| Cloudflare Managed Ruleset | ...49e6b538 | 100534         | Web Shell Activity           | Log             | Block      | This was released as ...82fe4e7f |

Jan 13, 2025
1. ### [WAF Release - 2025-01-13](https://edgetunnel-b2h.pages.dev/changelog/post/2025-01-13-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset                    | Rule ID     | Legacy Rule ID | Description                                                                                   | Previous Action | New Action | Comments      |
| -------------------------- | ----------- | -------------- | --------------------------------------------------------------------------------------------- | --------------- | ---------- | ------------- |
| Cloudflare Managed Ruleset | ...f49e5840 | 100704         | Cleo Harmony - Auth Bypass - CVE:CVE-2024-55956, CVE:CVE-2024-55953                           | Log             | Block      | New Detection |
| Cloudflare Managed Ruleset | ...a6d43bc2 | 100705         | Sentry - SSRF                                                                                 | Log             | Block      | New Detection |
| Cloudflare Managed Ruleset | ...ce6311bb | 100706         | Apache Struts - Remote Code Execution - CVE:CVE-2024-53677                                    | Log             | Block      | New Detection |
| Cloudflare Managed Ruleset | ...2233da1f | 100707         | FortiWLM - Remote Code Execution - CVE:CVE-2023-48782, CVE:CVE-2023-34993, CVE:CVE-2023-34990 | Log             | Block      | New Detection |
| Cloudflare Managed Ruleset | ...e31d972a | 100007C\_BETA  | Command Injection - Common Attack Commands                                                    |                 | Disabled   |               |

Jan 09, 2025
1. ### [New Rules Overview Interface](https://edgetunnel-b2h.pages.dev/changelog/post/2025-01-09-rules-overview/)  
[ Rules ](https://edgetunnel-b2h.pages.dev/rules/)  

**Rules Overview** gives you a single page to manage all your [Cloudflare Rules](https://edgetunnel-b2h.pages.dev/rules/).  
What you can do:

  * **See all your rules in one place** – No more clicking around.
  * **Find rules faster** – Search by name.
  * **Understand execution order** – See how rules run in sequence.
  * **Debug easily** – Use [Trace](https://edgetunnel-b2h.pages.dev/rules/trace-request/) without switching tabs.  
Check it out in [Rules > Overview ↗](https://dash.cloudflare.com/?to=/:account/:zone/rules/overview).

Jan 06, 2025
1. ### [WAF Release - 2025-01-06](https://edgetunnel-b2h.pages.dev/changelog/post/2025-01-06-waf-release/)  
[ WAF ](https://edgetunnel-b2h.pages.dev/waf/)  

| Ruleset             | Rule ID     | Legacy Rule ID | Description                                                                                               | Previous Action | New Action | Comments      |
| ------------------- | ----------- | -------------- | --------------------------------------------------------------------------------------------------------- | --------------- | ---------- | ------------- |
| Cloudflare Specials | ...9da08beb | 100678         | Pandora FMS - Remote Code Execution - CVE:CVE-2024-11320                                                  | Log             | Block      | New Detection |
| Cloudflare Specials | ...ecdf3d02 | 100679         | Palo Alto Networks - Remote Code Execution - CVE:CVE-2024-0012, CVE:CVE-2024-9474                         | Log             | Block      | New Detection |
| Cloudflare Specials | ...a40f2a35 | 100680         | Ivanti - Command Injection - CVE:CVE-2024-37397                                                           | Log             | Block      | New Detection |
| Cloudflare Specials | ...58ae3c89 | 100681         | Really Simple Security - Auth Bypass - CVE:CVE-2024-10924                                                 | Log             | Block      | New Detection |
| Cloudflare Specials | ...e37f2da6 | 100682         | Magento - XXE - CVE:CVE-2024-34102                                                                        | Log             | Block      | New Detection |
| Cloudflare Specials | ...5054c752 | 100683         | CyberPanel - Remote Code Execution - CVE:CVE-2024-51567                                                   | Log             | Block      | New Detection |
| Cloudflare Specials | ...dfe93d7b | 100684         | Microsoft SharePoint - Remote Code Execution - CVE:CVE-2024-38094, CVE:CVE-2024-38024, CVE:CVE-2024-38023 | Log             | Block      | New Detection |
| Cloudflare Specials | ...1454c856 | 100685         | CyberPanel - Remote Code Execution - CVE:CVE-2024-51568                                                   | Log             | Block      | New Detection |
| Cloudflare Specials | ...e92362e5 | 100686         | Seeyon - Remote Code Execution                                                                            | Log             | Block      | New Detection |
| Cloudflare Specials | ...b9f1c9f8 | 100687         | WordPress - Remote Code Execution - CVE:CVE-2024-10781, CVE:CVE-2024-10542                                | Log             | Block      | New Detection |
| Cloudflare Specials | ...0d7ca374 | 100688         | ProjectSend - Remote Code Execution - CVE:CVE-2024-11680                                                  | Log             | Block      | New Detection |
| Cloudflare Specials | ...a5260b70 | 100689         | Palo Alto GlobalProtect - Remote Code Execution - CVE:CVE-2024-5921                                       | Log             | Block      | New Detection |
| Cloudflare Specials | ...d007118b | 100690         | Ivanti - Remote Code Execution - CVE:CVE-2024-37404                                                       | Log             | Block      | New Detection |
| Cloudflare Specials | ...c3e49f64 | 100691         | Array Networks - Remote Code Execution - CVE:CVE-2023-28461                                               | Log             | Block      | New Detection |
| Cloudflare Specials | ...fcc6f5bb | 100692         | CyberPanel - Remote Code Execution - CVE:CVE-2024-51378                                                   | Log             | Block      | New Detection |
| Cloudflare Specials | ...b615335e | 100693         | Symfony Profiler - Auth Bypass - CVE:CVE-2024-50340                                                       | Log             | Block      | New Detection |
| Cloudflare Specials | ...09d08c8a | 100694         | Citrix Virtual Apps - Remote Code Execution - CVE:CVE-2024-8069                                           | Log             | Block      | New Detection |
| Cloudflare Specials | ...8aafb2f5 | 100695         | MSMQ Service - Remote Code Execution - CVE:CVE-2023-21554                                                 | Log             | Block      | New Detection |
| Cloudflare Specials | ...11b7a8c7 | 100696         | Nginxui - Remote Code Execution - CVE:CVE-2024-49368                                                      | Log             | Block      | New Detection |
| Cloudflare Specials | ...45954c7e | 100697         | Apache ShardingSphere - Remote Code Execution - CVE:CVE-2022-22733                                        | Log             | Block      | New Detection |
| Cloudflare Specials | ...f5311209 | 100698         | Mitel MiCollab - Auth Bypass - CVE:CVE-2024-41713                                                         | Log             | Block      | New Detection |
| Cloudflare Specials | ...b3e5e46e | 100699         | Apache Solr - Auth Bypass - CVE:CVE-2024-45216                                                            | Log             | Block      | New Detection |

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://edgetunnel-b2h.pages.dev/changelog/product-group/application-security/7/#page","headline":"Application security Changelog | Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/changelog/product-group/application-security/7/","inLanguage":"en","image":"https://edgetunnel-b2h.pages.dev/cf-twitter-card.png","publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"isPartOf":{"@type":"WebSite","@id":"https://edgetunnel-b2h.pages.dev/#website","name":"Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/"}}
```
