Skip to content

WAF - Leaked credentials detection now scans Authorization headers

UpdateUnverifiedAdded Sep 24, 2026

Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.

Topics: SQL

Cloudflare's release notes

More Cloudflare developer platform releases

Every Cloudflare developer platform release

Also shipped on Aug 20, 2026

Cloudflare in August 2026

Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.

New releases by email

Tuesday mornings: the week's data, AI and developer-tools releases, only in weeks when something shipped.

Double opt-in. Unsubscribe any time.