Cloudflare WAF 2026-09-30 更新:新增 GitLab
WAF - WAF Release - 2026-09-30
推荐理由
WAF 规则从 Log 变为 Block 属于破坏性变更,可能直接阻断正常业务流量。请检查受影响的 GitLab 及相关接口,确认无需调整白名单或自定义规则即可安全升级。
This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.
本次发布引入了新的检测机制,以增强对特定 GitLab 路径遍历漏洞的防护,同时新增了针对 HTTP 请求走私、目录遍历和命令注入尝试的高级通用规则。
Key Findings
主要发现
- CVE-2026-85706: A path traversal vulnerability affecting GitLab.
- CVE-2026-85706:影响 GitLab 的路径遍历漏洞。
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | ...cb14ded8 | N/A | Broken Access Control - Directory Traversal | Log | Block | This is a new detection. |
| Cloudflare Managed Ruleset | ...0364bd7e | N/A | HTTP Request Smuggling - Request Body Anomaly - Beta | Log | Block | This rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ...1489d892). |
| Cloudflare Managed Ruleset | ...d498a69a | N/A | Command Injection - Generic 8 - body - Beta | Disabled | Disabled | This rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ...413592e2). |
| Cloudflare Managed Ruleset | ...87ae8cfc | N/A | GitLab - Path Traversal- CVE:CVE-2026-85706 | Log | Block | This is a new detection. |
| Cloudflare Managed Ruleset | ...549f7356 | N/A | Generic - Request routing cache inconsistency | N/A | Block | This is a new detection. |
| 规则集 | 规则 ID | 旧版规则 ID | 描述 | 先前操作 | 新操作 | 备注 |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | ...cb14ded8 | N/A | 访问控制缺陷 - 目录遍历 | 记录日志 | 阻止 | 此为新增检测。 |
| Cloudflare Managed Ruleset | ...0364bd7e | N/A | HTTP 请求走私 - 请求体异常 - Beta | 记录日志 | 阻止 | 此规则已合并至原始规则“HTTP/2 请求走私 - 请求体异常”(ID: ...1489d892)。 |
| Cloudflare Managed Ruleset | ...d498a69a | N/A | 命令注入 - 通用 8 - body - Beta | 已禁用 | 已禁用 | 此规则已合并至原始规则“命令注入 - 通用 8 - body”(ID: ...413592e2)。 |
| Cloudflare Managed Ruleset | ...87ae8cfc | N/A | GitLab - 路径遍历 - CVE:CVE-2026-85706 | 记录日志 | 阻止 | 此为新增检测。 |
| Cloudflare Managed Ruleset | ...549f7356 | N/A | 通用 - 请求路由缓存不一致 | N/A | 阻止 | 此为新增检测。 |
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力