Cloudflare experienced a 25-minute service disruption on December 5, 2025, affecting 28% of HTTP traffic due to a configuration change in its Web Application Firewall (WAF) while mitigating a React Server Components vulnerability (CVE-2025-55182). The incident was triggered by a Lua code error in FL1 proxy when disabling an internal tool, causing HTTP 500 errors. Cloudflare confirmed no cyber attack was involved and detailed the technical flaw—attempting to index a nil value in ruleset logic. The post-mortem highlights lessons from a similar November 18 outage, outlining resilience improvements like enhanced rollouts, versioning, and ‘fail-open’ error handling. This analysis offers deep insights into cloud infrastructure reliability, security best practices, and the risks of rapid configuration changes, making it valuable for professionals in network security and DevOps.
原文链接:Hacker News
最新评论
照片令人惊艳。万分感谢 温暖。
氛围绝佳。由衷感谢 感受。 你的博客让人一口气读完。敬意 真诚。
实用的 杂志! 越来越好!
又到年底了,真快!
研究你的文章, 我体会到美好的心情。
感谢激励。由衷感谢
好久没见过, 如此温暖又有信息量的博客。敬意。
很稀有, 这么鲜明的文字。谢谢。