Cloudflare
Security & compliance
Stability
0-RTT early data enabled (request replay risk)
Part of the Edge TLS posture check · fix arrives as a guide
What it is
0-RTT early data is enabled on the zone.
Why it matters
Early data is sent before the handshake completes, so it can be captured and replayed. Cloudflare only allows it for requests that are already safe, which rules out the duplicate-charge case — what remains is a replayed GET reaching an origin that treats GETs as state-changing, and early data having no forward secrecy.
How to fix it
Disable 0-RTT unless you have confirmed that every endpoint reachable this way is idempotent. The latency saving is small relative to the class of bug it introduces.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.