{
  "id": 13308491,
  "title": "When Cloudflare WAF detections fail, choose a rule response for each route",
  "url": "https://urgent.news/2026/10/10/when-cloudflare-waf-detections-fail-choose-a-rule-response-for-each",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T02:48:56.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/davekurian/when-cloudflare-waf-detections-fail-choose-a-rule-response-for-each-route-idk"
  },
  "original_language": "en",
  "account": "Cloudflare's new cf.appsec.request.failed_detections field provides security teams with detection IDs for failed requests on sensitive routes. This does not alter the detectors' behavior, but allows the Rules engine to make an explicit choice on how to handle these failures. A failed detection is distinct from a detection match; the former indicates a supported detector could not complete normally, while the latter means a detector recognized a condition it was designed to detect. The field exposes the latter to supported rules and is not a global fail-open or fail-closed switch. It serves as a signal for your policy to inspect, not as a default behavior. The field is an array of strings, including IDs for failures reported by various detectors. It is available on all plans but only includes detections and rule features your plan supports. The field is evaluated before custom rules and can be used in specific rule types at zone and account level, rate limiting rules at zone and account level, and request-header rules at zone level. The choice of rule type depends on the scope and intended action. When using the field, separate the detector's failure from the policy decision. Treat it as a signal, not a verdict. An empty array means no failures were reported. An example of a rule expression could be len(cf.appsec.request.failed_detections) gt 0 to match any reported failure. Always validate before enforcing a new failure policy and consider the type of request and potential impact.",
  "summary": "A security detection can fail before it decides whether a request is safe. That is a different event from a detection matching an attack. If your app depends on edge screening for a sensitive route, what happens when the detector reports an error? Cloudflare's new cf.appsec.request.failed_detections field gives your Rules engine the detection IDs that reported failures for a request. It does not…",
  "key_points": [
    "The field is an array of strings, indicating failures reported by various detectors.",
    "Use len(cf.appsec.request.faileddetections) gt 0 to match any reported failure in rule expressions."
  ],
  "editors_take": "Cloudflare's new field for failed detections gives security teams more nuanced control over handling detection failures on sensitive routes, allowing for more targeted and informed policy decisions.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}