Skip to content
Cloudflare Docs

Changelog

New updates and improvements at Cloudflare.

Subscribe to RSS
View all RSS feeds

hero image

WAF Release - Scheduled changes for 2025-12-08

Announcement DateRelease DateRelease BehaviorLegacy Rule IDRule IDDescriptionComments
2025-12-012025-12-08Unchanged (rule remains disabled)N/A Anomaly:Body - Large 2Default action changes from Log to Block while the rule stays disabled. If you override and enable the rule, review recent log events to ensure blocking will not affect legitimate traffic.
2025-12-012025-12-08LogN/A Atlassian Confluence - Code Injection - CVE:CVE-2021-26084 - BetaThis is a beta detection and will replace the action on original detection "Atlassian Confluence - Code Injection - CVE:CVE-2021-26084" (ID: )
2025-12-012025-12-08LogN/A PostgreSQL - SQLi - Copy - BetaThis is a beta detection and will replace the action on original detection "PostgreSQL - SQLi - COPY" (ID: )
2025-12-012025-12-08LogN/A SQLi - AND/OR MAKE_SET/ELT - BetaThis is a beta detection and will replace the action on original detection "SQLi - AND/OR MAKE_SET/ELT" (ID: )
2025-12-012025-12-08LogN/A SQLi - Benchmark Function - BetaThis is a beta detection and will replace the action on original detection "SQLi - Benchmark Function" (ID: )
2025-12-012025-12-08LogN/A SQLi - Comment - BetaThis is a beta detection and will replace the action on original detection "SQLi - Comment" (ID: )
2025-12-012025-12-08LogN/A SQLi - Comparison - BetaThis is a beta detection and will replace the action on original detection "8166da327a614849bfa29317e7907480" (ID: )
2025-12-012025-12-08LogN/A Generic Rules - Command Execution - BodyThis is a new detection.
2025-12-012025-12-08LogN/A Generic Rules - Command Execution - HeaderThis is a new detection.
2025-12-012025-12-08LogN/A Generic Rules - Command Execution - URIThis is a new detection.
2025-12-012025-12-08LogN/A SQLi - String Function - BetaThis is a beta detection and will replace the action on original detection "SQLi - String Function" (ID: )
2025-12-012025-12-08LogN/A SQLi - Sub Query - BetaThis is a beta detection and will replace the action on original detection "SQLi - Sub Query" (ID: )
2025-12-012025-12-08LogN/A SQLi - Tautology - URI - BetaThis is a beta detection and will replace the action on original detection "SQLi - Tautology - URI" (ID: )
2025-12-012025-12-08LogN/A SQLi - WaitFor Function - BetaThis is a beta detection and will replace the action on original detection "SQLi - WaitFor Function" (ID: )
2025-12-012025-12-08LogN/A SQLi - AND/OR Digit Operator Digit 2 - BetaThis is a beta detection and will replace the action on original detection "SQLi - AND/OR Digit Operator Digit" (ID: )
2025-12-012025-12-08LogN/A SQLi - Equation 2 - BetaThis is a beta detection and will replace the action on original detection "SQLi - Equation" (ID: )
2025-12-012025-12-08LogN/A WordPress, Drupal - Code Injection, Deserialization - Stream Wrapper - CVE:CVE-2019-11831, CVE:CVE-2019-6339, CVE:CVE-2018-1000773 - BetaThis is a beta detection and will replace the action on original detection "Wordpress, Drupal - Code Injection, Deserialization - Stream Wrapper - CVE:CVE-2019-11831, CVE:CVE-2019-6339, CVE:CVE-2018-1000773" (ID: )
2025-12-012025-12-08LogN/A XWiki - Remote Code Execution - CVE:CVE-2025-24893 - BetaThis is a beta detection and will replace the action on original detection "XWiki - Remote Code Execution - CVE:CVE-2025-24893" (ID: )
2025-12-012025-12-08LogN/A Django SQLI - CVE:CVE-2025-64459This is a new detection.