TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Camelgate NPM Outage (Cloudflare)

122 pointsby bavarianbobabout 2 months ago
EDIT: Back online?!<p>NPM discussion: <a href="https:&#x2F;&#x2F;github.com&#x2F;npm&#x2F;cli&#x2F;issues&#x2F;8203" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;npm&#x2F;cli&#x2F;issues&#x2F;8203</a><p>NPM incident: <a href="https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s" rel="nofollow">https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s</a><p>Cloudflare messaging: <a href="https:&#x2F;&#x2F;www.cloudflarestatus.com&#x2F;incidents&#x2F;gshczn1wxh74" rel="nofollow">https:&#x2F;&#x2F;www.cloudflarestatus.com&#x2F;incidents&#x2F;gshczn1wxh74</a><p>GitHub issue: <a href="https:&#x2F;&#x2F;github.com&#x2F;sindresorhus&#x2F;camelcase&#x2F;issues&#x2F;114" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sindresorhus&#x2F;camelcase&#x2F;issues&#x2F;114</a><p>Anyone experiencing npm outage that&#x27;s more than just the referenced camelcase package?

9 comments

tom_usherabout 2 months ago
Seems to be a change in Cloudflare&#x27;s managed WAF ruleset - any site using that will have URLs containing &#x27;camel&#x27; blocked due to the &#x27;Apache Camel - Remote Code Execution - CVE:CVE-2025-29891&#x27; (a9ec9cf625ff42769298671d1bbcd247) rule.<p>That rule can be overridden if you&#x27;re having this issue on your own site.
评论 #43550699 未加载
评论 #43549123 未加载
评论 #43550078 未加载
Recursingabout 2 months ago
Any path with the word &quot;camel&quot; seem to trigger this: <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;search?q=camel" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;search?q=camel</a> | <a href="https:&#x2F;&#x2F;registry.npmjs.org&#x2F;camel123" rel="nofollow">https:&#x2F;&#x2F;registry.npmjs.org&#x2F;camel123</a> | <a href="https:&#x2F;&#x2F;registry.yarnpkg.com&#x2F;camel456" rel="nofollow">https:&#x2F;&#x2F;registry.yarnpkg.com&#x2F;camel456</a><p>Some discussion here <a href="https:&#x2F;&#x2F;github.com&#x2F;npm&#x2F;cli&#x2F;issues&#x2F;8203" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;npm&#x2F;cli&#x2F;issues&#x2F;8203</a><p>Edit: this is resolved now <a href="https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s" rel="nofollow">https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s</a>
pvgabout 2 months ago
This is not CF WAF&#x27;s first rodeo <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20421538">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=20421538</a><p>Cementing its track record as a product that mostly doesn&#x27;t do anything except for occasionally break the internet here and there to keep things fun and interesting.
评论 #43552686 未加载
评论 #43550388 未加载
评论 #43550290 未加载
nwalters512about 2 months ago
The npm folks have officially acknowledged an incident now: <a href="https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s" rel="nofollow">https:&#x2F;&#x2F;status.npmjs.org&#x2F;incidents&#x2F;hdtkrsqp134s</a>
miyuruabout 2 months ago
Outsourcing WAF is a double-edged sword.<p>I would have thought a large company like GitHub or Microsoft can have their own WAF team for their apps.<p>(NPM is owned by GitHub, and GitHub is owned by Microsoft)
klysmabout 2 months ago
This is what you get when you buy security as an add-on product
评论 #43557613 未加载
mplanchardabout 2 months ago
Glad you posted something, thought I was going nuts
drusepthabout 2 months ago
Is this also why unpkg has been up and down all morning?
评论 #43551882 未加载
time4teaabout 2 months ago
Scunthorpe problem