3 ms·
the cve isn't a zero day though how come cloudflare werent at the table for early disclosure?
by Already__Taken 10mo ago
the cve isn't a zero day though how come cloudflare werent at the table for early disclosure?
- flaminHotSpeedo 10mo agoDo you have a public source about an embargo period for this one? I wasn't able to find one
- charcircuit 10mo agoConsidering there were patched libraries at the time of disclosure, those libraries' authors must have been informed ahead of time.
- Pharaoh2 10mo agohttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components https://react.dev/blog/2025/12/03/critical-security-vulnerab... Privately Disclosed: Nov 29 Fix pushed: Dec 1 Publicly disclosed: Dec 3
- drysart 10mo agoThen even in the worst case scenario, they were addressing this issue two days after it was publicly disclosed. So this wasn't a "rush to fix the zero day ASAP" scenario, which makes it harder to justify ignoring errors that started occuring in a small scale rollout.
- ascorbic 10mo agoCloudflare did have early access, and had mitigation in place from the start. The changes that were being rolled out were in response to ongoing attempts to bypass those. Disclosure: I work at Cloudflare, but not on the WAF