A new XSS bypass was discovered for Cloudflare WAF. The payload used for the bypass is %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E. This bypass allows attackers to execute malicious scripts on websites protected by Cloudflare WAF. For more technical details, refer to the blogpost.