Cloudflare maintains a focused but strategically critical portfolio spanning content-delivery, security, and infrastructure-automation products, with particular depth in edge-computing platforms, DNS services, and developer tooling such as Warp, Pingora, and Wrangler. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the security-sensitive and high-throughput nature of edge and DNS infrastructure. The recurring exposure centers on input-validation deficiencies, resource-consumption handling, and authorization gaps across products that process untrusted network traffic and manage privileged operations, patterns consistent with the parsing and access-control demands of edge-layer and systems software. Defenders should monitor this vendor's advisories closely given the broad downstream impact of vulnerabilities in widely-used edge and developer infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudflare, Inc. over time
Of all the CVEs published by Cloudflare, Inc. as a CNA, 91.3% affect products that Cloudflare, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Cloudflare, Inc., 98.4% are self-published by Cloudflare, Inc. as a CNA.
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12523HIGH Summary
Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames.
Impact
HTTP/3 | Jul 14, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-1229CRITICAL The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.
E | Feb 24, 2026 | 9.8 | 32 | NO | NO |
CVE-2014-125026CRITICAL LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input. | Dec 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-2835CRITICAL An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1 | Mar 5, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-2833CRITICAL An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing | Mar 5, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-0933CRITICAL SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed d | Jan 20, 2026 | 9.9 | 31 | NO | NO |
CVE-2022-3320CRITICAL It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint | Oct 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-12707HIGH Summary
Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events.
Impact
quiche s | Jul 14, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-2836HIGH A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementat | Mar 5, 2026 | 8.1 | 28 | NO | NO |
CVE-2022-3512HIGH Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced o | Oct 28, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (64 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudflare, Inc..
Media articles that mention a CVE ID that affects a product developed by Cloudflare, Inc. — matched by CVE ID, not by vendor name.