
5/16/2025 · Sri Pulla, Martin Schwarzl, Trishna
What this post added
This post details Cloudflare's commitment to transparency in vulnerability reporting, aligning with CISA's "Secure by Design" pledge. It explains the process of issuing CVEs as a CVE Numbering Authority (CNA), including triage criteria and disclosure timelines. Notable CVEs related to Cloudflare products (quiche, WordPress plugin, WARP client) and external dependencies (BoringSSL impacting mTLS) are highlighted, demonstrating the practical application of these security practices.