6 ms·
Seems to be a change in Cloudflare's managed WAF ruleset - any site using that will have URLs containing 'camel' blocked due to the 'Apache Camel - Remote Code
by tom_usher 1y ago
Seems to be a change in Cloudflare's managed WAF ruleset - any site using that will have URLs containing 'camel' blocked due to the 'Apache Camel - Remote Code Execution - CVE:CVE-2025-29891' (a9ec9cf625ff42769298671d1bbcd247) rule.
That rule can be overridden if you're having this issue on your own site.
- cbovis 1y agoConfirmed here: https://www.cloudflarestatus.com/incidents/gshczn1wxh74 https://www.cloudflarestatus.com/incidents/gshczn1wxh74
- oncallthrow 1y agoWAFs are so shit
- ronsor 1y agoWAFs are literally "a pile of regexes can secure my insecure software"
- mschuster91 1y agoTo be fair to WAFs, most are more than just a pile of regexes. Things like detecting bot traffic - be it spammers or AI scrapers - are valuable (ESPECIALLY the AI scraper detection, because unlike search engines these things have zero context recognition or respect for robots.txt and will just happily go on and ingest very heavy endpoints), and the large CDN/WAF providers can do it even better because they can spot shit like automated port scanners, Metasploit or similar skiddie tooling across all the services that use them. Honestly what I'd _love_ to see is AWS, GCE, Azure, Fastly, Cloudflare and Akamai band together and share information about such bad actors, compile evidence lists and file abuse reports against their ISP - or in case the ISP is a "bulletproof hoster" or certain enemy states, initiate enforcement actors like governments to get these bad ISPs disconnected from the Internet.
- randunel 1y agoWhy would scrapes get blocked, is scrapping illegal?
- eitland 1y agoI don't know if it is, but I also don't think we are required to let dumb bots repeatedly assault or web sites if we can find a technical way to get around it.
- Xylakant 1y agoIt's very often not, but it's still the website owners property and if they choose so, they can show misbehaving guests the door and kindly ask to remain on the other side (aka block them). Large scale scraping puts substantial burden on web properties. I was paged the other night because someone decided it would be a great idea to throw 200 000rq/s for a few minutes at some publicly available volunteer run service.
- cluckindan 1y agoThey do mitigate known vulnerabilities.
- rcxdude 1y agoThey may mitigate known proofs of concept of vulnerabilities, and require a small amount of creativity to work around. At the cost of randomly breaking things.
- cluckindan 1y agoThat creativity takes time. WAFs are the first line of defence, buying some time for fixing the actual vulnerabilities.
- UltraSane 1y agoBut are they less shit than the shitty software they filter traffic for?
- internetter 1y ago> any site using that will have URLs containing 'camel' blocked What engineer at cloudflare thought this was a good resolution?
- Raed667 1y agoI doubt the system is that simple. No one wrote a rule saying `if url.contains("camel") then block()` it's probably an unintended side-effect
- keithwhor 1y agoIf this is a bet, I'll happily take the other side and give you 4:1 on it.
- dgfitz 1y agoMe too.
- ycombinatrix 1y agoAkamai has been doing precisely that for years & years...
- deleted 1y ago[deleted]
- benoau 1y agoI think you can include advertising/privacy block lists in that vein too, although that allows for the users to locally-correct any issues.
- isbvhodnvemrwvn 1y agoJudging by previous outages it was probably a poorly tested overcomplicated regex which matched to much.
- TacticalCoder 1y ago