HeadlinesBriefing favicon HeadlinesBriefing.com

Cloudflare BGP Route Leak Incident Analysis

Hacker News: Front Page •
×

On January 22, 2026, Cloudflare's network automation triggered an accidental BGP route leak from its Miami data center. A misconfigured routing policy advertised internal IPv6 prefixes to external peers and providers for 25 minutes, causing congestion, packet loss, and elevated latency. The company identified this as a mix of Type 3 and Type 4 route leaks according to RFC7908.

The error originated from a policy change meant to remove Bogotá data center announcements. Instead, a JunOS policy became overly permissive, matching any 'internal' route type and re-advertising them externally. This violated valley-free routing principles, funneling unintended traffic through Miami and disrupting both Cloudflare customers and third-party networks. The incident mirrors a similar 2020 outage.

Cloudflare's network team identified and reverted the faulty configuration within 28 minutes, pausing automation on the affected router. The company has since documented the event on Cloudflare Radar and published a detailed technical post-mortem. For network engineers, this underscores the critical need for rigorous testing of routing policy automation, as even minor configuration diffs can have widespread internet-wide consequences.