// Alert

Cloudflare threat report

Cloudflare's repositories were among 300+ high-impact open-source projects identified as vulnerable to Cordyceps, a CI/CD attack pattern disclosed in June 2026 by Novee Security. The weakness allows attackers with a free GitHub account to exploit malicious pull requests targeting pull_request_target and workflow_run triggers, potentially achieving code execution and access to repository secrets. Affected projects include those by Microsoft, Google, Apache, and the Python Software Foundation; all pipelines passed security checks despite exposure.

// Get alerts for Cloudflare