
Vulnerability disclosure on SSL for SaaS v1 (Managed CNAME)
8/1/2025
This post details a vulnerability in the older SSL for SaaS v1 (Managed CNAME) product, where IP-based routing and lack of domain ownership verification allowed for potential Man-in-the-Middle attacks. It explains the architectural difference between v1 and the newer Cloudflare for SaaS v2, highlighting how v2's verified custom hostname model with hostname verification and pre-validation closes this security gap. Compensating controls like an allowlist and WAF custom rules are implemented for remaining v1 users, and the post emphasizes the ongoing migration to the secure, validated v2 model.









