Comment by Already__Taken

2 months ago

the cve isn't a zero day though how come cloudflare werent at the table for early disclosure?

Do you have a public source about an embargo period for this one? I wasn't able to find one

Cloudflare did have early access, and had mitigation in place from the start. The changes that were being rolled out were in response to ongoing attempts to bypass those.

Disclosure: I work at Cloudflare, but not on the WAF