Origin IP Exposed waf bypass

Disclosed: 2026-05-14 13:38:42 By r00tsid To yuga_labs
Low
Vulnerability Details
Hello team, I have discovered that the https://52.6.254.246/ site exposed it's IP which could allow bypassing of anti-DDoS mechanisms i.e you are using Cloudflare for protection. For Originate IP address which I found from https://search.censys.io/ By using these IP address as a resolver instead of the intended addresses I'm able to access the service without going through the WAF, thus I'm able to forward unfiltered payloads to the service, as well as avoiding the common protections offered by Cloudflare, also being able to perform crippling denial-of-service towards the origin. ##IP: 52.6.254.246 ## Impact Cloudflare bypasses can have a significant impact, as any adversary is now able to communicate with the origin server directly, enabling them to perform unfiltered attacks (such as denial-of-service), and data retrieval.
Actions
View on HackerOne
Report Stats
  • Report ID: 1821085
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report