WAF - Leaked credentials detection now scans Authorization headers
UpdateUnverifiedAdded Sep 24, 2026
Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.
Topics: SQL
More Cloudflare developer platform releases
Every Cloudflare developer platform release| Date | Release | Type |
|---|---|---|
| Aug 20 | Browser Run - Run more headless browsers concurrently with Browser Rununverified Update | Update |
| Aug 20 | Containers - Use FUSE in local Containers developmentunverified Update | Update |
| Aug 20 | Durable Objects, Workers - View deployments for Durable Objects in the dashboardunverified Update | Update |
| Aug 20 | Cloudflare Fundamentals - Optional OAuth scopesunverified GA | GA |
| Aug 20 | Logs - New Logpush datasets and updated fields across multiple Logpush datasets in Cloudflare Logsunverified Update | Update |
| Aug 20 | Logs, Log Explorer - Per-zone post-quantum visibility in Logpush and Log Explorerunverified Update | Update |
| Aug 21 | CASB - Automatically remediate Microsoft 365 and Google Workspace findings with API-based CASB remediation policiesunverified Update | Update |
| Aug 21 | Data Loss Prevention - Test Data Loss Prevention profiles without sending traffic through Gatewayunverified Update | Update |
Also shipped on Aug 20, 2026
Cloudflare in August 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.