PatchSiren

Cloudflare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Cloudflare CVE published 2026-08-12

CVE-2026-11325

A remote code execution issue exists in the archived cloudflare/pages-action repository, specifically in src/index.ts, which can be exploited under certain GitHub Actions workflow configurations. This could lead to exposure of workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN. The repository has been deprecated since 2024 and will not receive further updates or security patches. Users of clou [truncated]

HIGH Cloudflare CVE published 2026-07-14

CVE-2026-12523

Cloudflare quiche's HTTP/3 layer is vulnerable to resource exhaustion via specially crafted HTTP/3 frames. The issue arises from pre-allocating memory based on declared frame length and not applying QPACK decompression limits correctly. This could enable an attacker to cause resource exhaustion, potentially leading to denial-of-service conditions. Users of Cloudflare quiche, particularly those exposed to [truncated]

MEDIUM Cloudflare CVE published 2026-07-02

CVE-2026-14440

The CVE-2026-14440 vulnerability affects Cloudflare Universal SSL, which adds Certification Authority Authorization (CAA) DNS records that override user-configured CAA records. The Universal SSL CAA records may be more permissive than user-configured records, allowing an attacker with appropriate network access to spoof domain validation and obtain a certificate for the target domain. This vulnerability h [truncated]