Skip to content

Commit 726abcb

Browse files
authored
Release-Feb-02-2026 - Add Changes (#28042)
* Release-Feb-02-2026 - Add Changes * Update 2026-02-02-waf-release.mdx Update 2026-02-02-waf-release.mdx
1 parent 1c81297 commit 726abcb

File tree

1 file changed

+63
-0
lines changed

1 file changed

+63
-0
lines changed
Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
---
2+
title: "WAF Release - 2026-02-02"
3+
description: Cloudflare WAF managed rulesets 2026-02-02 release
4+
date: 2026-02-02
5+
---
6+
7+
import { RuleID } from "~/components";
8+
9+
This week’s release introduces new detections for CVE-2025-64459 and CVE-2025-24893.
10+
11+
**Key Findings**
12+
13+
- CVE-2025-64459: Django versions prior to 5.1.14, 5.2.8, and 4.2.26 are vulnerable to SQL injection via crafted dictionaries passed to QuerySet methods and the `Q()` class.
14+
- CVE-2025-24893: XWiki allows unauthenticated remote code execution through crafted requests to the SolrSearch endpoint, affecting the entire installation.
15+
16+
<table style="width: 100%">
17+
<thead>
18+
<tr>
19+
<th>Ruleset</th>
20+
<th>Rule ID</th>
21+
<th>Legacy Rule ID</th>
22+
<th>Description</th>
23+
<th>Previous Action</th>
24+
<th>New Action</th>
25+
<th>Comments</th>
26+
</tr>
27+
</thead>
28+
<tbody>
29+
<tr>
30+
<td>Cloudflare Managed Ruleset</td>
31+
<td>
32+
<RuleID id="7a47683eacce4abd870ab2c630698ff3" />
33+
</td>
34+
<td>N/A</td>
35+
<td>XWiki - Remote Code Execution - CVE:CVE-2025-24893 2</td>
36+
<td>Log</td>
37+
<td>Block</td>
38+
<td>This is a new detection.</td>
39+
</tr>
40+
<tr>
41+
<td>Cloudflare Managed Ruleset</td>
42+
<td>
43+
<RuleID id="ad5c52f6ca334ef4a844e5e5da8ba7e6" />
44+
</td>
45+
<td>N/A</td>
46+
<td>Django SQLI - CVE:CVE-2025-64459</td>
47+
<td>Log</td>
48+
<td>Block</td>
49+
<td>This is a new detection.</td>
50+
</tr>
51+
<tr>
52+
<td>Cloudflare Managed Ruleset</td>
53+
<td>
54+
<RuleID id="f3a89a84e3744021a2f8e9291b138b3e" />
55+
</td>
56+
<td>N/A</td>
57+
<td>NoSQL, MongoDB - SQLi - Comparison</td>
58+
<td>Block</td>
59+
<td>Block</td>
60+
<td>Changed the description of the rule.</td>
61+
</tr>
62+
</tbody>
63+
</table>

0 commit comments

Comments
 (0)