3 ms·
Not expose the server IP is one practice (obfuscation) in a list of several options. But that alone would not solve the problem being a RCE from HTTP, that is
by sergsoares 10mo ago
Not expose the server IP is one practice (obfuscation) in a list of several options.
But that alone would not solve the problem being a RCE from HTTP, that is why edge proxy provider like Cloudflare[0] and Fastfy[1] proactivily added protections in his WAF products.
Even cloudflare had an outage trying to protect his customers[3].
- [0] https://blog.cloudflare.com/waf-rules-react-vulnerability/ https://blog.cloudflare.com/waf-rules-react-vulnerability/
- [1] https://www.fastly.com/blog/fastlys-proactive-protection-critical-react-rce-cve-2025-55182 https://www.fastly.com/blog/fastlys-proactive-protection-cri...
- [2] https://blog.cloudflare.com/5-december-2025-outage/ https://blog.cloudflare.com/5-december-2025-outage/
- j45 9mo agoNo provider is perfect - It's totally possible to run your own FW behind it, or run CF Tunnel on a separate container that routes traffic to individual application containers using something like traefik, nginx proxy manager, etc.