Categories
privacy security

Incident report on memory leak caused by Cloudflare parser bug

This is quite serious. A lot of small (and not so small) websites uses Cloudflare for CDN and DDoS protection. The issue reported by Google’s Project Zero team indicates that a bug in Cloudflare’s processing causes potentially sensitive information to be leaked. This is already bad, but it is made worse due to caching servers keeping a copy of those information. Someone is compiling a list of notable websites affected. You are advised to change your passwords on those affected websites.

Last Friday, Tavis Ormandy from Google’s Project Zero contacted Cloudflare to report a security problem with our edge servers. He was seeing corrupted web pages being returned by some HTTP requests run through Cloudflare. It turned out that in some unusual circumstances, which I’ll detail below, our edge

Source: Incident report on memory leak caused by Cloudflare parser bug