Cloudflare CDN Defect Allowed Compromise Of 12% Of All Sites

July 19, 2021

The website security company Cloudflare recently fixed a critical vulnerability in its free and open-source CDNJS, which is expected to affect 12.7% of all websites on the internet.

Security researcher RyotaK discovered the vulnerability by finding a way to fully compromise Cloudflare’s CDNJS by tricking servers into executing arbitrary code.

The vulnerability, if exploited, could lead to a total compromise of the CDNJS infrastructure

After Cloudflare reported the vulnerability, the Cloudflare team took drastic action and worked on several fixes to address the issue.

Although the original solution attempted to fix the symlink vulnerability, the complexity of the CDNJS ecosystem caused further fixes to be made over the following weeks.

CNDJS serves millions of websites with approximately 4,000 publicly available JavaScript and CSS libraries stored publicly on GitHub.

For more information, read the original story in Bleeping Computer.

Top Stories

Related Articles

June 5, 2026 Security researchers have disclosed a new denial-of-service attack called HTTP/2 Bomb that can overwhelm major web servers more...

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn