WAFs cannot protect against client-side supply chain attacks because they don't intercept the fetch to the 3rd party endpoint and therefore have no visibility into the JavaScript files from the 3rd party sources. When attackers compromise popular libraries or CDNs, the malicious updates continue to be delivered from the same trusted domains that your WAF has whitelisted. Your WAF sees legitimate requests to approved sources and allows them through, completely unaware that the content has been weaponized by attackers.
Back to blog
Can a WAF protect against supply chain attacks on third-party JavaScript libraries?
Wednesday, September 3rd, 2025
Updated September 5th, 2025S
Simon Wijckmans
S
More About Simon Wijckmans
Founder and CEO of c/side. Building better security against client-side executed attacks, and making solutions more accessible to smaller businesses. Web security is not an enterprise only problem.