Earlier quoted context omitted.
One thing to keep in mind when judging what's 'appropriate' is that Cloudflare was effectively responding to an ongoing security incident outside of their control (the React Server RCE vulnerability). Part of Cloudlfare's value proposition is being quick to react to such threats. That changes the equation a bit: any hour you wait longer to deploy, your customers are actively getting hacked through a known high-severi…
the cve isn't a zero day though how come cloudflare werent at the table for early disclosure?
Disclosure: I work at Cloudflare, but not on the WAF