Skip to main content
SecurityMay 3, 2026 · 3 min read

CDN vendors patch bypass chain affecting HTML-rewriting WAF rules

A crafted chunk transfer could desynchronize rule evaluation from the origin under rare HTTP/2 coalescing setups.

CDN vendors patch bypass chain affecting HTML-rewriting WAF rules

Most enterprises were already protected after February’s pre-announcement, but multi-tenant SaaS edges lagged on configuration defaults.

Validate that your WAF still inspects full request bodies for POST forms that mutate HTML at the edge.

Red-team scripts circulating on researcher forums are noisy—focus on vendor-provided regression tests instead of ad-hoc scanners in production paths.

Editorial briefing only. Verify facts against primary sources and your counsel before acting.

By Inseo

Related briefings