Skip to content
Cloudflare ยท Cloud and hostingJul 2, 2019, 13:42 UTC

WAF regular expression exhausts CPU worldwide for 27 minutes

CriticalDeploymentUpdated 20h ago
Jul 2, 13:42 UTCJul 2, 14:09 UTC
Duration
27m
Impact
Critical
Root cause
Deployment
Cloudflare, 90 days
50 incidents
Affected
CDNWAFGlobal

Lesson: Rules and regexes are code; stage them, and use an engine with guaranteed linear time for untrusted input.

What happened

A new WAF rule for XSS detection contained a regular expression with catastrophic backtracking. Deployed globally through an automatic process, it pushed CPU to 100% on every HTTP server and the network dropped traffic for 27 minutes.

More from Cloudflare

Full history

Also caused by deployment or rollout

All
StartedIncidentDuration
Aug 2014:43 UTCIntermittent failures creating agent tasksGitHub9h 54m
Aug 2000:31 UTC[Medium] Issue with Microsoft Office Integration and Box EditBox1h 13m
Aug 622:22 UTCTrouble Using Search Bar For Some AdminsSlack2h 44m
Jul 2110:23 UTCJob runs failing at the git clone stepdbt Labs2h 29m
Jul 1907:33 UTCSome EMEA customers experiencing Git clone failures (403 errors) on thier accountsdbt Labs6h 22m
Jul 200:17 UTCTraces, spans, logs inaccesible for query or ingestion in de and usSentry3h 39m

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.