Skip to content
Cloudflare ยท Cloud and hostingJul 2, 2019, 13:42 UTC

WAF regular expression exhausts CPU worldwide for 27 minutes

CriticalDeploymentUpdated 37h ago
Jul 2, 13:42 UTCJul 2, 14:09 UTC
Duration
27m
Impact
Critical
Root cause
Deployment
Cloudflare, 90 days
56 incidents
Affected
CDNWAFGlobal

Lesson: Rules and regexes are code; stage them, and use an engine with guaranteed linear time for untrusted input.

What happened

A new WAF rule for XSS detection contained a regular expression with catastrophic backtracking. Deployed globally through an automatic process, it pushed CPU to 100% on every HTTP server and the network dropped traffic for 27 minutes.

More from Cloudflare

Full history

Also caused by deployment or rollout

All
StartedIncidentDuration
Aug 2014:43 UTCIntermittent failures creating agent tasksGitHub9h 54m
Aug 2000:31 UTC[Medium] Issue with Microsoft Office Integration and Box EditBox1h 13m
Aug 622:22 UTCTrouble Using Search Bar For Some AdminsSlack2h 44m
Jul 2220:20 UTCSome users may have experienced errors when accessing Amplitude.Amplitude0m
Jul 2110:23 UTCJob runs failing at the git clone stepdbt Labs2h 29m
Jul 1907:33 UTCSome EMEA customers experiencing Git clone failures (403 errors) on thier accountsdbt Labs6h 22m

Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Outages by email

Saturday mornings: the week's major outages, new postmortems and disclosed breaches, only in weeks that had some.

Double opt-in. Unsubscribe any time.