2025年12月5日,由于在React2Shell修复过程中的配置变化有缺陷,云层断裂,导致28%的交通中断25分钟。
A Cloudflare outage on Dec. 5, 2025, due to a flawed config change during a React2Shell fix, disrupted 28% of traffic for 25 minutes.
2025年12月5日的云层断电,影响约28%的HTTP交通量25分钟,其原因是在应对关键反应2壳脆弱性(CVE-2025-55182)时进行了有缺陷的配置改变。
A Cloudflare outage on December 5, 2025, affecting about 28% of HTTP traffic for 25 minutes, was caused by a flawed configuration change made while addressing the critical React2Shell vulnerability (CVE-2025-55182).
问题源于在修复过程中使WAF测试工具失效,触发FL1代理规则模块中的错误,而非网络攻击。
The issue stemmed from disabling a WAF testing tool during a fix, triggering a bug in the FL1 proxy’s rules module, not a cyberattack.
脆弱性允许远程代码执行,并被威胁行为体利用,包括与中国有联系的团体。
The vulnerability allows remote code execution and has been exploited by threat actors, including China-linked groups.
Cloudflare快速恢复服务,并正在审查11月类似停电之后的变革进程。
Cloudflare restored service quickly and is reviewing its change processes after a similar November outage.