Website Security & Threat Management
Vulnerability disclosure on SSL for SaaS v1 (Managed CNAME)

Vulnerability disclosure on SSL for SaaS v1 (Managed CNAME)

8/1/2025 · Mia Malden, Albert Pedersen, Trishna, Ross Jacobs

What this post added

This post details a vulnerability found in the older SSL for SaaS v1 (Managed CNAME) product, which relied on IP-based routing and lacked domain ownership verification. It explains how this architecture could be exploited and highlights the mitigation strategy: the phased transition to the more secure Cloudflare for SaaS (v2), which enforces hostname verification. The post also outlines compensating controls for remaining v1 customers and emphasizes the ongoing commitment to security and transparency.

Read the original post ↗