
8/1/2025 · Mia Malden, Albert Pedersen, Trishna, Ross Jacobs
What this post added
This post details a vulnerability found in the older SSL for SaaS v1 (Managed CNAME) product, which relied on IP-based routing and lacked domain ownership verification. It explains how this architecture could be exploited and highlights the mitigation strategy: the phased transition to the more secure Cloudflare for SaaS (v2), which enforces hostname verification. The post also outlines compensating controls for remaining v1 customers and emphasizes the ongoing commitment to security and transparency.