Back to news

AWS tightens firewall defaults; Cloudflare exposes hyper HTTP library bug

Two infrastructure developments this week signal heightened attention to reliability gaps in foundational networking layers.

AWS tightens firewall defaults; Cloudflare exposes hyper HTTP library bug

What happened

AWS quietly shifted the default stateful drop action in Network Firewall from a bidirectional behavior to a server-directed-only mode for all newly created firewall policies. The change is automatic for new policies and requires no manual intervention, but it reflects AWS's acknowledgment that the previous default could interrupt legitimate connections. Separately, Cloudflare disclosed that a rearchitecting effort on its Images product binding inadvertently exposed a latent defect in the widely used open-source hyper HTTP library — a bug that had persisted undetected across multiple major versions of the library.

Why it matters for your business

The AWS update is a low-friction reliability improvement, but teams managing existing firewall policies should audit whether their current configurations still reflect best practice, since only newly created policies inherit the updated default. The hyper bug discovery carries a broader warning: hyper underpins HTTP handling in a significant share of Rust-based network services, meaning applications that have never been modified may still be running vulnerable or misbehaving code inherited from the dependency. The practical takeaway is that internal refactoring work — not just external security audits — can surface critical issues in third-party libraries, and dependency review should be a standing item on engineering roadmaps rather than a reactive exercise.

What to watch next

The hyper maintainers will likely issue a patch release, and teams using Rust networking stacks should monitor the hyper changelog and pin versions carefully until a fix is confirmed stable. On the AWS side, watch for similar default-hardening moves across other Network Firewall policy settings as cloud providers continue to shift security responsibility upstream. Broader adoption of software bill of materials practices would accelerate the kind of dependency visibility that caught the hyper bug in this case.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp