Tell HN: Camelgate NPM Outage (Cloudflare)

117 points33 commentsa day ago
tom_usher

Seems to be a change in Cloudflare's managed WAF ruleset - any site using that will have URLs containing 'camel' blocked due to the 'Apache Camel - Remote Code Execution - CVE:CVE-2025-29891' (a9ec9cf625ff42769298671d1bbcd247) rule.

That rule can be overridden if you're having this issue on your own site.

show comments
pvg

This is not CF WAF's first rodeo https://news.ycombinator.com/item?id=20421538

Cementing its track record as a product that mostly doesn't do anything except for occasionally break the internet here and there to keep things fun and interesting.

show comments
nwalters512

The npm folks have officially acknowledged an incident now: https://status.npmjs.org/incidents/hdtkrsqp134s

miyuru

Outsourcing WAF is a double-edged sword.

I would have thought a large company like GitHub or Microsoft can have their own WAF team for their apps.

(NPM is owned by GitHub, and GitHub is owned by Microsoft)

klysm

This is what you get when you buy security as an add-on product

show comments
mplanchard

Glad you posted something, thought I was going nuts

drusepth

Is this also why unpkg has been up and down all morning?

show comments