we_are_coded.by CODE · The world, decoded
БГ
Concept

WAF (web application firewall)

The BasicsUpdated on 16 August 2026we are coded

A WAF is a filter in front of the site - it watches incoming requests and stops the harmful ones before they reach the application itself. It doesn't fix the hole. It guards it while you patch it.

Checked on16 August 2026
A WAF (Web Application Firewall) is a layer in front of a site or shop that checks every incoming request and blocks the ones that look like an attack - for instance, an attempt to slip a foreign command into the database or run outside code. It works by rules: known attack patterns get stopped automatically.

The distinction that confuses people: a WAF doesn't fix the bug in the code. The hole stays exactly where it was. The WAF just stands in front of it and won't let the attack through - like a guard in front of a broken lock. That's why providers like Cloudflare push out "managed rules" the moment a new vulnerability appears. They buy everyone time to update.

So it should never replace the patch. The shield only guards against the known form of the attack, and only while you stand behind it. Pull the site out from behind the WAF-based shield, or let attackers come up with a new variant, and only one thing is left that actually closes the hole. Updating.

The visual is generated code art. No third-party images.
Official primary sources
→OWASP: Web Application Firewall (definition)