2017 Cloudbleed — CDN memory leak exposed customer data
Data compromised
Emails, usernames, passwords, cookies, auth tokens, encryption keys
Technical writeup
Cloudbleed: A buffer overflow bug in Cloudflare's HTML parser caused memory from CDN edge servers to leak into customer responses. The vulnerability occurred over 18 million times before being corrected. Leaked data included emails, usernames, passwords, private chat messages, HTTP cookies, authentication tokens, and encryption keys. Affected sites included Uber, FitBit, OKCupid, and 1Password. Bug potentially dated back to September 2016; leaked data was cached by search engines.
Root cause
Buffer overflow in HTML parser