IT

Mar 24, 2025 cloudflare api httpsonly httplock security infosec

Cloudflare now blocks all unencrypted traffic to its API endpoints

Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com.

cloudflare-24-03-25.png

The move prevents unencrypted API requests from being sent, even accidentally, to eliminate the risk of sensitive information being exposed in cleartext traffic before the server closes the HTTP connection and redirects to a secure communication channel.

 

“Starting today, any unencrypted connection to api.cloudflare.com will be completely rejected,” reads Cloudflare’s announcement on Thursday.

 

“Developers should not expect a 403 Forbidden response any longer for HTTP connections, as we will prevent the underlying connection from being established by closing the HTTP interface entirely. Only secure HTTPS connections will be allowed to be established” - the internet services company added.

 

The Cloudflare API helps developers and system administrators to automate and manage Cloudflare services. It is used for DNS records management, firewall configuration, DDoS protection, caching, SSL settings, infrastructure deployment, accessing analytics data, and managing zero-trust access and security policies.

 

Previously, Cloudflare systems allowed API access over both HTTP (unencrypted) and HTTPS (encrypted), either by redirecting or rejecting HTTP.

 

However, as the company explains, even rejected HTTP requests may leak sensitive data like API keys or tokens before the server responds.

 

 

Such a sceario is more dangerous when the connection is over public or shared Wi-Fi networks where adversary-in-the-middle attacks are easier to pull off.

 

By disabling HTTP ports entirely for API access, Cloudflare blocks plaintext connections at the transport layer before any data is exchanged, enforcing HTTPS from the start.

 

Impact and next steps


The change immediately affects anyone using HTTP on the Cloudflare API service. Scripts, bots, and tools relying on the protocol will break.

 

The same applies to legacy systems and automated clients, IoT devices, and low-level clients that don’t support or don’t default to HTTPS due to improper configuration.

 

For customers with websites on Cloudflare, the company prepares to release a free option towards the end of the year that will disable HTTP traffic in a safe way.

 

Cloudflare data indicates that a small but significant percentage of roughly 2.4% of all internet passing through its systems is still done over the insecure HTTP protocol. When automated traffic is taken into account, the HTTP share jumps to nearly 17%.

 

Customers can track HTTP vs HTTPS traffic on their dashboard under Analytics & Logs > Traffic Served Over SSL before opting in, to estimate the impact it will have on their environment.

load more

cloudflare-24-03-25.png

Cloudflare now blocks all unencrypted traffic to its API endpoints

Category: IT|Mar 24, 2025 | Author: Admin
Hacker-data_theft-23-03-25.png

RansomHub ransomware uses new Betruger ‘multi-function’ backdoor

Category: IT|Mar 23, 2025 | Author: Admin
UK-22-03-25.png

UK urges critical orgs to adopt quantum cryptography by 2035

Category: IT|Mar 22, 2025 | Author: Admin
GitHub__headpic-21-03-25.png

GitHub Action supply chain attack exposed secrets in 218 repos

Category: IT|Mar 21, 2025 | Author: Admin
Asphalt-Airborne-20-03-25.png

Microsoft lifts Windows 11 upgrade block after Asphalt 8 crash fix

Category: Microsoft|Mar 20, 2025 | Author: Admin
Govt_spy-19-03-25.png

WhatsApp patched zero-click flaw exploited in Paragon spyware attacks

Category: IT|Mar 19, 2025 | Author: Admin
rat_malware-18-02-25.png

New RAT malware used for crypto theft, reconnaissance

Category: Microsoft|Mar 18, 2025 | Author: Admin
GitHub-17-03-25.png

Supply chain attack on popular GitHub Action exposes CI/CD secrets

Category: IT|Mar 17, 2025 | Author: Admin
Exchange-Online-16-03-25.png

Week-long Exchange Online outage causes email failures, delays

Category: Microsoft|Mar 16, 2025 | Author: Admin
AI_robot_Windows_11-15-03-25.png

Windows Notepad to get AI text summarization in Windows 11

Category: Microsoft|Mar 15, 2025 | Author: Admin
Outlook-14-03-25.png

Microsoft says button to restore classic Outlook is broken

Category: Microsoft|Mar 14, 2025 | Author: Admin
GitLab-13-03-25.png

GitLab patches critical authentication bypass vulnerabilities

Category: IT|Mar 13, 2025 | Author: Admin
Firefox-12-03-25.png

Mozilla warns users to update Firefox before certificate expires

Category: Microsoft|Mar 12, 2025 | Author: Admin
Windows-headpic-11-03-25.png

Microsoft replacing Remote Desktop app with Windows App in May

Category: Microsoft|Mar 11, 2025 | Author: Admin
swiss-flag-10-03-25.png

Swiss critical sector faces new 24-hour cyberattack reporting rule

Category: IT|Mar 10, 2025 | Author: Admin
more