
2/10/2025 · Josephine Chow, June Slater, Bryton Herdes, Lucas Pardue
What this post added
This post details the discovery and mitigation of a broadcast address amplification vulnerability in Cloudflare's QUIC implementation. It explains how sending a QUIC Initial packet to a broadcast IP address could trigger a server CPU and reflection amplification attack. The vulnerability was traced to the way Cloudflare servers bind anycast IP ranges to their loopback interfaces, creating local and broadcast routes that, when targeted by a QUIC Initial packet to a broadcast address, could lead to excessive response packets. The fix involved modifying the server's packet handling logic to prevent this amplification vector.