I mean, on your origin you can control the firewall of your own webserver. If you only accept https from the cloudflare IPs everyone using your Url should be patched thought cloudflare without issue and the attack wouldn't be much of a problem as they would be rejected. I use this method on some of my website at work.
Not an issue if you only accept request from the cloudflare IPs and reject everything else