{"record":"Cloudflare evidence record","url":"https://nexalign.io/vendors/cloudflare","vendor":{"slug":"cloudflare","name":"Cloudflare","domain":"cloudflare.com","category":"cloud","categoryLabel":"Cloud and sovereign cloud"},"lastChecked":"2026-07-17T16:21:54.770Z","coverage":{"earliest":"2023-09-26T01:51:14.000Z","latest":"2026-07-17T16:21:54.770Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":58,"kindsOfSource":3,"attributedAdvisories":9,"knownExploited":0,"registerEntriesNotAttributable":30,"practitionerThreads":16,"independentItems":3,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":39,"latest":"2026-07-14T15:51:28.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":16,"latest":"2026-06-04T13:00:51.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-17T16:21:54.770Z"}],"advisories":{"shown":6,"total":9,"truncated":true,"items":[{"id":"CVE-2026-12523","description":"Summary\n\n\n\nCloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames.","severity":"high","cvss":7.5,"knownExploited":false,"date":"2026-07-14T15:51:28.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43748"]},{"id":"CVE-2026-12707","description":"Summary\n\n\n\nCloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events.","severity":"high","cvss":7.5,"knownExploited":false,"date":"2026-07-14T15:18:24.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43716"]},{"id":"CVE-2026-14440","description":"Description:\n\n\n\n\nTo issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone.","severity":"high","cvss":7.6,"knownExploited":false,"date":"2026-07-01T22:35:10.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41207"]},{"id":"CVE-2026-11941","description":"Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions.","severity":"medium","cvss":5.6,"knownExploited":false,"date":"2026-06-19T09:55:54.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38003"]},{"id":"CVE-2026-2836","description":"A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction.","severity":"high","cvss":8.4,"knownExploited":false,"date":"2026-03-04T23:44:56.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9512"]},{"id":"CVE-2026-2835","description":"An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests.","severity":"critical","cvss":9.3,"knownExploited":false,"date":"2026-03-04T23:32:41.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9511"]}]},"practitionerThreads":{"shown":5,"total":16,"truncated":true,"items":[{"title":"VoidZero Is Joining Cloudflare","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48398055","date":"2026-06-04T13:00:51.000Z"},{"title":"Cloudflare Turnstile requiring fingerprintable WebGL","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48345840","date":"2026-05-31T14:13:20.000Z"},{"title":"Cloudflare to cut about 20% of its workforce","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48054423","date":"2026-05-07T20:23:37.000Z"},{"title":"Agents can now create Cloudflare accounts, buy domains, and deploy","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48031684","date":"2026-05-06T03:10:33.000Z"},{"title":"Tell HN: Docker pull fails in Spain due to football Cloudflare block","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47738883","date":"2026-04-12T12:28:57.000Z"}]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Cloudflare Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/cloud-application-platforms/vendor/cloudflare","date":null},{"title":"Cloudflare Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/cloudflare-1701452315","date":null},{"title":"Cloudflare - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Cloudflare","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 30 register entries mention Cloudflare without naming a product of Cloudflare as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}