Below you will find pages that utilize the taxonomy term “Ssrf”
Posts
Cloudflare Used AI to Attack Its Own WAF and Found 49 Gaps, Mostly SSRF
Cloudflare just published the results of an experiment that every API developer should read, even if you’ll never run a firewall. The company put frontier AI models inside a test harness and told them to get past its own Web Application Firewall.
They found gaps. Not many, but the pattern of what got through is the real lesson.
What Cloudflare did
The test started with attack payloads the WAF already blocked. Instead of replaying a fixed list, the models looked at how each attempt was handled and proposed a tweak for the next one: different encoding, different placement in the request, different delivery. They had no access to the WAF rules or source code. Pure black box.