Cloudflare has resolved a high-impact request normalization flaw within its global edge reverse-proxy and Web Application Firewall (WAF) inspection pipeline. The flaw, categorized under CWE-444: Inconsistent Interpretation of HTTP Requests, allowed remote attackers to bypass managed security rules by exploiting delimiter parsing discrepancies between edge inspection proxies and origin web servers.
Vulnerability Mechanism: HTTP/2 to HTTP/1.1 Downgrade Ambiguity (CWE-444)
Cloudflare terminates client connections at its edge data centers, frequently accepting HTTP/2 or HTTP/3 from browser clients while proxying connections to upstream origin servers over HTTP/1.1 keep-alive pools. The vulnerability occurred when an attacker crafted an HTTP/2 request with pseudo-headers containing malformed newline characters within folded custom header values:
// Ambiguous Header Downgrade Pattern at Edge Gateway
:method = POST
:path = /api/v1/checkout
custom-gateway-token = abc\r\nContent-Length: 0\r\n\r\nPOST /admin/exec HTTP/1.1\r\nHost: origin.corp.internalImpact on Downstream Origin Infrastructures
Because the edge WAF evaluated the request based solely on the outermost HTTP/2 frame, it classified the payload as benign. However, when serialized onto the upstream HTTP/1.1 stream, the origin web server (such as Nginx, Apache, or Node.js) parsed the injected header as a delimiter separating two distinct HTTP requests. This allowed smuggled payloads—including SQL injection, remote command execution, or unauthorized administrative actions—to execute against backend databases completely uninspected.
Origin Protection Defense Recommendations
- Enforce Strict HTTP Protocol Validation: Configure origin reverse proxies to reject any HTTP/1.1 request exhibiting ambiguous whitespace, header folding, or multiple length declarations.
- Deploy Cloudflare Authenticated Origin Pulls (mTLS): Enforce client certificate validation between Cloudflare edge servers and origin hosts to block direct-to-origin IP scanning.
- Transition to End-to-End HTTP/2 or gRPC: Upgrade backend application gateways to maintain native HTTP/2 connectivity directly from edge proxies to application containers.



