It would be possible for an ISP to MITM the traffic between Cloudflare and the origin server since it can be configured to be done via unencrypted HTTP or non-trusted certs on HTTPS (flexible SSL). See https://medium.com/@karthikb351/airtel-is-sniffing-and-censo... for an example of Cloudflare serving a MITM notice page for pirate bay.