Cloudflare published a technical post-mortem describing a 25-minute IPv6 BGP route leak that originated in Miami and propagated broadly to external networks, causing congestion, packet loss, and an estimated ~12 Gbps of dropped throughput. The incident was triggered during a routing policy change intended to limit advertisement of Bogotá-related IPv6 prefixes in Miami; deletion of a prefix list made the export policy overly permissive, allowing internal iBGP IPv6 routes to be accepted and then advertised to external neighbors. Cloudflare characterized the event as a hybrid of RFC 7908 Type 3 and Type 4 route leaks, where routes learned from peers/providers were inappropriately redistributed to other peers/providers, violating “valley-free” routing expectations.
Reporting highlighted that while the primary impact was availability and performance degradation, route leaks can also carry a security risk when misrouted traffic is attracted to networks not intended to transit it, creating conditions that can resemble or enable interception in BGP hijacking scenarios. In this case, the misadvertisements were automatically propagated to BGP peers in the region, and in environments using strict source/provider-based filtering, some traffic would be discarded entirely rather than delivered, amplifying outage-like symptoms beyond Cloudflare’s direct customer base.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Cloudflare later disclosed technical details of the incident, attributing it to an accidental router policy misconfiguration and comparing it to a similar July 2020 event. The company said it would implement stricter export safeguards, CI/CD policy validation, improved early detection, and support for RFC 9234 and RPKI ASPA to reduce future route leaks.
Shortly after the leak began, Cloudflare detected the issue, manually reverted the router configuration, and paused automation to stop further propagation. The company ended the impact within about 25 minutes and later reverted the triggering code change before safely re-enabling automation.
On January 22, 2026, Cloudflare accidentally leaked internal IPv6 routes from Miami to external peers after a routing policy change meant to stop Miami from advertising Bogotá prefixes became overly permissive. The incident caused congestion, packet loss, and roughly 12 Gbps of dropped traffic, and was characterized as a mix of RFC 7908 Type 3 and Type 4 route leaks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.