cloudflare has 11 CVEs on record between 2021 and 2025. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. Most affected products: github.com/cloudflare/cfrpki (7), github.com/cloudflare/circl (2), github.com/cloudflare/cloudflared (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- github.com/cloudflare/cfrpki 7
- github.com/cloudflare/circl 2
- github.com/cloudflare/cloudflared 1
- github.com/cloudflare/goflow/v3 1
Worst active — by depth score
CVE-2021-3910High· 7.5NUL character in ROA causes OctoRPKI to crash42CVE-2023-1314High· 7.5cloudflared's Installer has Local Privilege Escalation Vulnerability41CVE-2022-2529High· 7.5Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package41CVE-2021-3761High· 7.5OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values41CVE-2021-3908Medium· 5.9Infinite certificate chain depth results in OctoRPKI running forever33
cloudflare vulnerabilities
CVEs affecting cloudflare, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2025-8556Low· 3.7CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CVE-2023-1732Medium· 5.3Improper random reading in CIRCL
Improper random reading in CIRCL
CVE-2023-1314High· 7.5cloudflared's Installer has Local Privilege Escalation Vulnerability
cloudflared's Installer has Local Privilege Escalation Vulnerability
CVE-2022-3616Medium· 5.4OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
CVE-2022-2529High· 7.5Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
CVE-2021-3911Medium· 4.2Misconfigured IP address field in ROA leads to OctoRPKI crash
Misconfigured IP address field in ROA leads to OctoRPKI crash
CVE-2021-3912Medium· 4.2OctoRPKI crashes when processing GZIP bomb returned via malicious repository
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
CVE-2021-3908Medium· 5.9Infinite certificate chain depth results in OctoRPKI running forever
Infinite certificate chain depth results in OctoRPKI running forever
CVE-2021-3909Medium· 4.4Infinite open connection causes OctoRPKI to hang forever
Infinite open connection causes OctoRPKI to hang forever
CVE-2021-3910High· 7.5NUL character in ROA causes OctoRPKI to crash
NUL character in ROA causes OctoRPKI to crash
CVE-2021-3761High· 7.5OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values