Cloudflare introduces field for WAF detection failures, allows custom rule responses

Cloudflare has introduced a new field, cf.appsec.request.failed_detections, that reports when a security detector fails to complete its analysis. This field provides detection IDs but does not automatically change request outcomes or detector behavior. Administrators can now create rules to explicitly handle these failures, choosing actions like blocking, challenging, or allowing the request. The field covers failures from multiple detection systems including content scanning, WAF scoring, and AI prompt analysis. It is available across all Cloudflare plans and can be used in custom rules, rate limiting rules, and request-header rules.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in