Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.
Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.
Ask the host to allowlist Cloudflare's published IP ranges, then raise PHP workers or enable a page cache so the origin answers within the 15-second edge timeout.
WordPress has its own failure mode, but Cloudflare Error 522 has a wider set of causes. The most common one overall is: The origin firewall silently drops Cloudflare's IP ranges.
Allowlist Cloudflare's IP ranges with an accept rule, and make sure the default policy does not drop them earlier in the chain.
Probing the origin address directly shows whether it is reachable from outside Cloudflare, which immediately tells you whether the fault is the firewall or the host.
Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.
Ask the host to allowlist Cloudflare's published IP ranges, then raise PHP workers or enable a page cache so the origin answers within the 15-second edge timeout.
Cloudflare tried to open a connection to the origin and nothing answered before the timeout. Usually a firewall silently dropping Cloudflare's traffic, an overloaded origin, or a wrong origin IP.