It was not caused by a bug in Ragel, though.
The author of this post wants uncompromising safety, ragel does not allow for that - programmer error can introduce memory unsafety. They even explicitly call out Cloudbleed.
[0] https://blog.cloudflare.com/incident-report-on-memory-leak-c...
> The Ragel code we wrote contained a bug that caused the pointer to jump over the end of the buffer and past the ability of an equality check to spot the buffer overrun.