Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cloudflare, Inc.

First CVE: Oct 2, 2020Active for: 6 yearsTotal CVEs: 64
36.1
VTI Score
Medium

Cloudflare maintains a focused but strategically critical portfolio spanning content-delivery, security, and infrastructure-automation products, with particular depth in edge-computing platforms, DNS services, and developer tooling such as Warp, Pingora, and Wrangler. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the security-sensitive and high-throughput nature of edge and DNS infrastructure. The recurring exposure centers on input-validation deficiencies, resource-consumption handling, and authorization gaps across products that process untrusted network traffic and manage privileged operations, patterns consistent with the parsing and access-control demands of edge-layer and systems software. Defenders should monitor this vendor's advisories closely given the broad downstream impact of vulnerabilities in widely-used edge and developer infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
64
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cloudflare, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2020
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Self-Reporting Analysis

Of all the CVEs published by Cloudflare, Inc. as a CNA, 91.3% affect products that Cloudflare, Inc. develops as a vendor.

91.3%
Self-reported: 63 (91.3%)
Third-party: 6 (8.7%)

Of all the CVEs published that affect products developed by Cloudflare, Inc., 98.4% are self-published by Cloudflare, Inc. as a CNA.

98.4%
Self-published: 63 (98.4%)
Other CNAs: 1 (1.6%)

Products(22 total)

Top CVEs

Signals from CVEs in this vendor scope (64 CVEs).

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-12523HIGH
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3
Jul 14, 20267.532NONO
CVE-2026-1229CRITICAL
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. E
Feb 24, 20269.832NONO
CVE-2014-125026CRITICAL
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
Dec 27, 20229.832NONO
CVE-2026-2835CRITICAL
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1
Mar 5, 20269.131NONO
CVE-2026-2833CRITICAL
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing
Mar 5, 20269.131NONO
CVE-2026-0933CRITICAL
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed d
Jan 20, 20269.931NONO
CVE-2022-3320CRITICAL
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint
Oct 28, 20229.831NONO
CVE-2026-12707HIGH
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche s
Jul 14, 20267.530NONO
CVE-2026-2836HIGH
A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementat
Mar 5, 20268.128NONO
CVE-2022-3512HIGH
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced o
Oct 28, 20228.828NONO
View all 64 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products64 CVEs
33%
52%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (23.4%)
Network44 (68.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (7.8%)
Attack Complexity
Low59 (92.2%)
High5 (7.8%)
Unknown0 (0.0%)
User Interaction
None51 (79.7%)
Unknown0 (0.0%)
Required13 (20.3%)
Privileges Required
Low19 (29.7%)
High0 (0.0%)
None45 (70.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (64 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudflare, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cloudflare, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cloudflare, Inc.'s Products

View all 2 CNAs →

Top CWEs