Skip to content

Commit 4bf7a8f

Browse files
[WAF] Update changelogs (#26989)
* [WAF] Update changelogs * Update src/content/changelog/waf/2025-12-05-rcs-vuln.mdx Co-authored-by: Jun Lee <[email protected]> --------- Co-authored-by: Jun Lee <[email protected]>
1 parent de16403 commit 4bf7a8f

File tree

2 files changed

+7
-17
lines changed

2 files changed

+7
-17
lines changed
Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,11 @@
11
---
22
title: Increased WAF payload limit for all plans
3-
description: The WAF now runs on requests with a body of up to 1 MB
3+
description: Updating WAF to run on requests body of up to 1MB
44
date: 2025-12-05
55
---
66

7-
We are increasing the maximum request-payload size the WAF inspects to 1 MB across all plans. This enhancement strengthens our detection capabilities for React RCE (CVE-2025-55182) by ensuring the WAF can fully analyse React payloads up to their standard maximum size. Long term limits might change based on plans in the future.
7+
Cloudflare WAF now inspects request-payload size of up to 1 MB across all plans to enhance our detection capabilities for React RCE (CVE-2025-55182).
88

99
**Key Findings**
1010

11-
React payloads commonly have a default maximum size of 1 MB. Cloudflare WAF previously inspected up to 128 KB on Enterprise plans, with even lower limits on other plans.
12-
13-
**Impact**
14-
15-
All WAF rules now evaluate up to 1 MB of request payload data, improving coverage and detection accuracy.
11+
React payloads commonly have a default maximum size of 1 MB. Cloudflare WAF previously inspected up to 128 KB on Enterprise plans, with even lower limits on other plans.

src/content/changelog/waf/2025-12-05-waf-max-payload-size-change.mdx

Lines changed: 4 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -4,20 +4,14 @@ description: We are changing the maximum request-payload size inspected by the C
44
date: 2025-12-05
55
---
66

7-
We are reinstating the maximum request-payload size the Cloudflare WAF inspects to the following values:
8-
9-
| | Free | Professional | Business | Enterprise |
10-
| -------------------------------- | ---- | ------------ | -------- | ---------- |
11-
| WAF scans request payload up to: | 1 MB | 8 KB | 8 KB | 128 KB |
7+
We are reinstating the maximum request-payload size the Cloudflare WAF inspects, with WAF on Enterprise zones inspecting up to 128 KB.
128

139
**Key Findings**
1410

15-
On December 5, 2025, we initially attempted to increase the maximum WAF payload limit to 1 MB across all plans. However, an automatic rollout for all customers proved impractical because the increase led to a surge in false positives. This issue was particularly notable within the Cloudflare Managed Ruleset and the Cloudflare OWASP Core Ruleset, impacting customer traffic.
11+
On December 5, 2025, we initially attempted to increase the maximum WAF payload limit to 1 MB across all plans. However, an automatic rollout for all customers proved impractical because the increase led to a surge in false positives for existing managed rules.
1612

17-
Consequently, we have decided to revert this change. Our Free plans will maintain the 1 MB limit as they are not experiencing an increase in false positives.
13+
This issue was particularly notable within the Cloudflare Managed Ruleset and the Cloudflare OWASP Core Ruleset, impacting customer traffic.
1814

1915
**Impact**
2016

21-
Customers on paid plans can increase the limit to 1 MB for any of their zones by contacting Cloudflare Support. Free zones are already protected up to 1 MB and do not require any action.
22-
23-
The initial increase in the size of the body inspected by the WAF may result in a higher rate of false positives being triggered in both the Cloudflare Managed Ruleset and the Cloudflare OWASP Core Ruleset. This higher rate should revert back to a normal value once the new limits are in place.
17+
Customers on paid plans can increase the limit to 1 MB for any of their zones by contacting Cloudflare Support. Free zones are already protected up to 1 MB and do not require any action.

0 commit comments

Comments
 (0)