Executive Summary
Google Cloud Security has published an official advisory detailing a high-severity security bypass flaw in Google Cloud Armor, the distributed Web Application Firewall (WAF) and DDoS mitigation service protecting workloads on Google Cloud Platform (GCP). Tracked under CVE-2026-56214, the flaw carries a CVSS v3.1 base score of 7.5 (High) and impacted HTTP/2 traffic streams inspected by Cloud Armor Adaptive Protection rules.
Cloud Armor Adaptive Protection leverages machine learning models to detect Layer 7 distributed denial-of-service (DDoS) attacks and malicious web traffic anomalies. Under specific conditions involving rapid HTTP/2 stream multiplexing and continuation frame encoding, an adversary could structure request headers such that backend compute instances processed the payload while Cloud Armor's edge inspection engine evaluated the connection as benign.
Technical Root Cause: HTTP/2 Continuation Frame Parser Inconsistency
The vulnerability stemmed from a header parsing desynchronization between Google's globally distributed edge proxy tier (Google Front End / GFE) and the Cloud Armor WAF rule evaluation engine. When processing large HTTP request headers split across multiple HTTP/2 CONTINUATION frames, the Cloud Armor parser truncated the internal evaluation buffer upon encountering specific non-standard padding byte sequences.
Consequently, malicious payloads—such as SQL injection syntax, cross-site scripting strings, or automated credential stuffing headers—located after the padding sequence were ignored by Cloud Armor's inspection filters. However, when the GFE forwarded the reassembled HTTP stream to upstream Google Kubernetes Engine (GKE) or Cloud Run workloads, the backend HTTP parser processed the complete request, effectively circumventing all perimeter WAF rules.
Packet Stream Desynchronization:
[Attacker Client]
│ (HTTP/2 HEADERS frame + Crafted CONTINUATION frame with padding)
▼
[Cloud Armor Edge WAF] ─── Truncates inspection buffer at padding boundary ───> Passes as Clean
▼
[Google Cloud Load Balancer (GFE)]
│ (Reassembles full un-truncated HTTP request)
▼
[Backend Service (GKE / Cloud Run)] ─── Executes un-inspected malicious payload!
Cloud Blast Radius & Attack Vectors
The ability to bypass Cloud Armor WAF rules allowed threat actors to:
- Circumvent Adaptive Protection rate limits designed to thwart high-volume Layer 7 credential stuffing and web scraping.
- Deliver targeted web application exploit payloads (e.g., Log4Shell, command injection) directly to backend microservices without triggering security policies.
- Evade geographic and IP reputation blocklists by masking client fingerprint headers within padded continuation frames.
Remediation Actions Taken & Guidance for GCP Customers
Because Cloud Armor is a fully managed cloud service, Google deployed automated patch updates across all global edge locations without requiring customer downtime. However, cloud architects should verify the following configuration settings:
- Verify Security Policy Logs: Inspect Cloud Logging for
jsonPayload.enforcedSecurityPolicy.outcometo verify that all HTTP/2 traffic is logging expected policy decisions. - Enforce Backend Header Validation: Ensure that upstream application containers (e.g. Nginx, Envoy, Spring Boot) implement strict RFC 7540 HTTP/2 compliance checks to drop non-standard continuation frames at the container ingress tier.
- Enable Cloud Armor Threat Intelligence: Activate Google's managed threat intelligence rulesets across all external HTTPS load balancers.



