Skip to content

Incidents involving:

Cloudflare, Inc.

Vulnerability exploitResolved

Cloudflare "Cloudbleed" memory leak

A buffer-overflow bug in Cloudflare's edge servers caused them to leak adjacent chunks of memory — including passwords, cookies, and private messages from other customers — into web pages, where some were cached by search engines. The flaw was active for months before Google's Project Zero discovered it.

Victim
Cloudflare, Inc.