Cloudflare CDN Defect Allowed Compromise Of 12% Of All Sites

The website security company Cloudflare recently fixed a critical vulnerability in its free and open-source CDNJS, which is expected to affect 12.7% of all websites on the internet.

Security researcher RyotaK discovered the vulnerability by finding a way to fully compromise Cloudflare’s CDNJS by tricking servers into executing arbitrary code.

The vulnerability, if exploited, could lead to a total compromise of the CDNJS infrastructure

After Cloudflare reported the vulnerability, the Cloudflare team took drastic action and worked on several fixes to address the issue.

Although the original solution attempted to fix the symlink vulnerability, the complexity of the CDNJS ecosystem caused further fixes to be made over the following weeks.

CNDJS serves millions of websites with approximately 4,000 publicly available JavaScript and CSS libraries stored publicly on GitHub.

For more information, read the original story in Bleeping Computer.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.