VULN-141859: Normalize request path when using access rules
With the previous changes made to normalize request paths, we faced some issues: * Regressions in Next.js route groups: https://github.com/cloudflare/cloudflared/issues/1719 * WordPress trailing slashes: https://github.com/cloudflare/cloudflared/issues/1717 This PR attempts to fix a vulnerability regarding un-normalized request paths using a different approach: instead of mutating `req.URL.Path` before forwarding to the origin, we compute a cleaned path used only for ingress rule selection, leaving the original request completely untouched. This separates the security classification decision from request proxying. Since this can be a breaking change, we are adding it disabled by default and will only enable it in future releases.
M
Miguel da Costa Martins Marcelino committed
059f86a8ddde4f0d71fc97e85dc58522d8baa43a
Parent: ad3c6d1
Committed by João "Pisco" Fernandes <joaocarlos@cloudflare.com>
on 9/29/2026, 4:51:37 PM