The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Yes—researchers demonstrated how a Cloudflare customer could route requests to another customer’s origin server through Cloudflare and potentially bypass protections configured for the victim’s Cloudflare zone. The September 2023 report described two risky configurations: using Cloudflare’s shared Authenticated Origin Pulls certificate and relying only on Cloudflare IP allowlisting at the origin. The report showed a proof of concept, not confirmed attacks against real customers.
How a Cloudflare customer could bypass another customer’s protections
Cloudflare normally sits between a website’s visitors and its origin server. A site owner can apply controls such as a web application firewall (WAF) at Cloudflare’s edge. Those controls help only when requests to the origin pass through the intended protections—and when the origin verifies that incoming connections are trusted in the right way.
In its September 28, 2023 disclosure, security consultancy Certitude said that two origin-hardening approaches trusted Cloudflare infrastructure generally without tying that trust to the protected customer’s own zone or account. In the proof of concept, an attacker configured a domain on their own Cloudflare account to point to the victim’s origin IP. The attacker’s domain did not apply the victim’s WAF rules, and the origin accepted traffic because it appeared to come through Cloudflare.
The issue was a cross-tenant trust-boundary problem, not a claim that Cloudflare’s entire network had been compromised. Certitude’s technical disclosure describes the demonstration and its findings.
#1 Best Overall
Which origin-protection setups were affected?
Authenticated Origin Pulls with Cloudflare’s shared certificate
Authenticated Origin Pulls uses client-certificate authentication between Cloudflare and a customer’s origin. Certitude said the shared Cloudflare certificate confirms that a request came from Cloudflare’s network, but does not establish that it came through the victim’s specific zone. An origin configured to accept that shared certificate could therefore trust traffic routed through another Cloudflare tenant.
Cloudflare’s current guidance recommends uploading a customer-specific certificate for stricter security. That approach adds certificate setup and management work and may be harder to scale across many origins. Authenticated Origin Pulls is available to all customers and requires Full or Full (strict) encryption mode, according to Cloudflare’s origin-protection documentation, last updated April 20, 2026. Cloudflare’s Authenticated Origin Pulls overview explains the feature.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Allowlisting Cloudflare IP addresses
An origin firewall can allow requests from Cloudflare IP ranges and reject connections from other addresses. This blocks many direct connections, but Cloudflare IP addresses are shared infrastructure: the allowlist alone does not identify which Cloudflare customer initiated a request. Certitude said another tenant could send traffic through Cloudflare that the victim’s origin would accept. Cloudflare currently describes IP allowlisting as “Moderately secure” and lists IP spoofing as a challenge in its origin-protection guidance.
What the disclosure does—and does not—establish
Certitude reported the issue to Cloudflare through HackerOne on March 16, 2023. The report was initially closed as “Informative.” Certitude published its disclosure on September 28, then updated it on October 4 to say Cloudflare had raised the severity to High (7.5) and announced documentation and dashboard changes. That score is a severity rating, not a count of affected customers or evidence of an attack.
Rank #3
The proof of concept establishes that the described configuration could provide a path around the victim’s edge rules. The reviewed accounts do not establish that attackers used it against real customers, that any customer was compromised, or how many sites used the affected settings. SecurityWeek’s September 29, 2023 report covered the disclosure while it was unfolding.
How to protect an origin server now
Cloudflare’s current documentation lists several ways to protect an origin. They differ in whether they bind trust to a customer, whether the origin remains publicly reachable, and how much configuration or ongoing maintenance they require.
Rank #4
| Option | What it does | Availability and trade-offs |
|---|---|---|
| Customer-specific Authenticated Origin Pulls certificate | Authenticates Cloudflare-to-origin connections using a certificate uploaded by the customer, rather than relying solely on Cloudflare’s shared certificate. | Available to all customers; requires Full or Full (strict) encryption mode. Cloudflare says it provides stricter security, but certificate setup and management add work and may not scale easily across many origins. |
| Cloudflare Tunnel | Uses outbound-only connections, so the origin does not need a publicly routable IP address. | Available to all customers; requires installing and operating the cloudflared daemon. |
| HTTP header or host-header validation | Adds checks at the origin to restrict which requests the application or server accepts. | Requires additional application or server configuration. Cloudflare warns that basic authentication can be vulnerable to replay attacks, and some valid product configurations can override Host headers. |
| Cloudflare IP allowlisting | Restricts connections to Cloudflare IP ranges. | Available to all customers, but Cloudflare rates it “Moderately secure.” It does not, by itself, identify the originating Cloudflare tenant. |
| Dedicated egress IPs | Lets an origin firewall permit narrower, account-reserved egress IPs. | Cloudflare’s current documentation describes dedicated CDN egress IPs through Smart Shield Advanced, labels the service Enterprise-only, and says network-level firewall policies are required. Availability and product packaging may change. |
Cloudflare’s documentation also recommends reducing the chance that an origin IP is exposed. Review DNS-only records that may reveal the address, hide the origin IP where possible, and consider rotating it after onboarding if historical DNS records could expose an earlier address. These steps complement origin authentication and firewall controls; they do not replace choosing a trust mechanism that matches the risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choosing a defense that fits your setup
- For a customer-specific identity check: use a customer-uploaded Authenticated Origin Pulls certificate, with the associated certificate deployment and renewal work.
- To avoid a public origin route: consider Cloudflare Tunnel, which requires the
cloudflareddaemon. - For an additional origin-side check: configure appropriate header or host validation, accounting for application behavior and Cloudflare product configurations.
- For firewall restrictions: treat Cloudflare IP allowlisting as a network filter, not proof that traffic came through your own zone. Dedicated egress IPs may enable narrower rules where the service is available.
Certitude said Cloudflare’s announced changes included guidance encouraging per-hostname and per-zone Authenticated Origin Pulls, host-header validation, and protecting the confidentiality of origin IP addresses. Its original disclosure referred to Aegis for dedicated egress IPs; Cloudflare’s April 2026 documentation uses Smart Shield Advanced for dedicated CDN egress IPs. Use Cloudflare’s current documentation for present-day product names and availability.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

