Google Project Zero security researcher Tavis Ormandy discovered Cloudbleed bug in CloudFlare. The bug is named after the Heartbleed vulnerability that was discovered in 2014. Cloudflare is a content delivery network and web security provider that helps optimize safety and performance of over 5.5 million websites on the Internet. The vulnerability is so severe that it also affects mobile apps as well as big-name websites. Cloudbleing could have exposed a range of sensitive information, including passwords, cookies and tokens used to authenticate users.
Source: https://thehackernews.com/2017/02/cloudflare-vulnerability.html