Home / Software & Gaming / Security / A Cloudflare bug has exposed passwords and sensitive data, lots of sites affected

A Cloudflare bug has exposed passwords and sensitive data, lots of sites affected

It looks like Cloudflare has been suffering from a bug recently, causing the passwords, cookies and tokens used to authenticate users by millions of sites to leak. Cloudflare is a security and performance tool that is used by 5.5 million websites, including big names like Reddit, Discord, Patreon and more. However, due to a myriad of factors, a bug has been present over the last five months.

First traces of the security flaw date back to the 22nd of September but the greatest impact came between the 13th and 18th of February, which is when the bug became more widely known. Cloudflare has fixed the issue but unfortunately the bug was active for so long that hackers will have already had plenty of opportunity to access user data by making web requests to affected websites.

Image Source: Hacker News. 

Writing in a blog post published yesterday, Cloudflare CTO, John Graham-Cumming explained that “the bug was serious because the leaked memory could contain private information and because it had been cached by search engines”. However, the company is “satisfied that search engine caches have now been cleared” and no more malicious exploits remain.

Google's Tavis Ormandy released his own response to this security breach, criticising Cloudflare for ‘downplaying the risk' involved in this breach. Users on GitHub have put together a long list of sites and services that use Cloudflare, so if you want to know if you need to change your password for anything specific, then you can find the list, HERE.

KitGuru Says: This is a pretty major leak so it is well worth checking if any of your accounts could have been compromised. Change passwords, use two-factor authentication and stay safe out there. 

Become a Patron!

Check Also

Marvel Rivals has a major security issue enabling Remote Code Execution

A Remote Code Execution exploit has been discovered in Marvel Rivals, allowing hackers to remotely spread malware through the game.

One comment

  1. I see you’re using the right words. “Could have” – I have so far reached out to around 8 of the large companies on the list and they have received messages from Cloudflare stating that they had no data leaked for their site. They’re still investigating and the sites given the clear are also still investigating. But try not to scare monger the people with this article.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!