{"id":208313,"date":"2026-03-09T20:51:57","date_gmt":"2026-03-09T19:51:57","guid":{"rendered":"https:\/\/liora.io\/en\/?p=208313"},"modified":"2026-08-09T18:28:30","modified_gmt":"2026-08-09T17:28:30","slug":"cloudflare-new-api-scanner","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/cloudflare-new-api-scanner","title":{"rendered":"Why Cloudflare\u2019s New API Scanner Changes Everything"},"content":{"rendered":"\n<p><strong>The new scanner employs a <strong>stateful approach<\/strong> that understands logical sequences and data dependencies within APIs, a significant departure from traditional stateless security tools that treat each request independently, according to <strong>Cloudflare&#8217;s blog announcement<\/strong>. This methodology specifically targets business logic flaws that conventional scanners miss.<\/strong><\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"how-it-works\">How It Works<\/h2>\n\n\n<p>The scanner operates through a sophisticated multi-step process. First, it ingests a customer&#8217;s <strong>OpenAPI specification<\/strong> to construct an &#8220;API call graph&#8221; that maps relationships between different endpoints. <strong>Cloudflare&#8217;s Workers AI platform<\/strong> then analyzes this graph to automatically infer data dependencies, even when naming conventions differ across endpoints.<\/p>\n\n\n<p>The system executes scans using two authenticated contexts: an &#8220;owner&#8221; who creates resources and an &#8220;attacker&#8221; who attempts unauthorized access. When the attacker successfully manipulates resources they shouldn&#8217;t control, the scanner flags a <strong>critical vulnerability<\/strong>.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"market-impact\">Market Impact<\/h2>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Screenshot of an API credentials interface showing key details and options for managing secrets.\" class=\"wp-image-208311\" decoding=\"async\" height=\"572\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-1024x572.jpg\" style=\"width:100%;height:auto\" width=\"1024\" srcset=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-1024x572.jpg 1024w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-300x167.jpg 300w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-768x429.jpg 768w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-1536x857.jpg 1536w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-2048x1143.jpg 2048w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-440x246.jpg 440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-785x438.jpg 785w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-210x117.jpg 210w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/api-credentials-user-interface-115x64.jpg 115w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n<p>The beta release, available now to all <strong>API Shield customers<\/strong>, initially focuses on <strong>Broken Object Level Authorization (BOLA)<\/strong>, ranked as the top threat on the OWASP API Security Top 10 list. Cloudflare plans to expand coverage to include SQL injection and cross-site scripting vulnerabilities in the near future, the company stated.<\/p>\n\n\n<p>This launch positions <strong>Cloudflare<\/strong> directly against specialized API security vendors like <strong>Salt Security<\/strong> and <strong>Noname Security<\/strong>, as well as traditional application security testing providers including <strong>Checkmarx<\/strong> and <strong>Invicti<\/strong>. By bundling advanced scanning capabilities into its existing security suite, Cloudflare offers customers a compelling alternative to standalone solutions.<\/p>\n\n\n<p>The scanner&#8217;s deep integration with Cloudflare&#8217;s edge network creates a unique advantage. It combines passive traffic analysis from API Discovery tools with active vulnerability testing, enabling real-time verification of potential threats identified in live traffic, all within a single platform.<\/p>\n\n\n<p>For data protection, <strong>Cloudflare<\/strong> employs <strong>HashiCorp&#8217;s Vault Transit Secret Engine<\/strong> to encrypt customer credentials, ensuring they remain secure throughout the scanning process. The company has not yet disclosed specific detection accuracy metrics or future pricing models for the service.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Cloudflare launched an open beta Monday of its AI-powered Web and API Vulnerability Scanner, a new security tool that automatically detects complex flaws in web applications and APIs. The scanner, integrated into Cloudflare&#8217;s API Shield service, uses artificial intelligence to map API behaviors and identify critical vulnerabilities like Broken Object Level Authorization, addressing the top threat facing modern web services.<\/p>\n","protected":false},"author":87,"featured_media":208312,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2417],"class_list":["post-208313","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=208313"}],"version-history":[{"count":2,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208313\/revisions"}],"predecessor-version":[{"id":210846,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208313\/revisions\/210846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/208312"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=208313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=208313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}