Zum Inhalt springen

Cloudflare Release Notes

1.616 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Verbesserte Dataset-Konfiguration in Log Explorer

Log Explorer bietet im Dashboard eine überarbeitete Dataset-Konfiguration mit gruppierter Feldauswahl, Felddetails, Massenauswahl und Ingestion-Filtern.

Log Explorer has a refreshed dataset configuration experience in the Cloudflare dashboard. The new controls make it easier to choose which fields and events Log Explorer ingests.

  • Grouped field selection organizes fields by category and shows the number selected in each group.
  • Field details identify each field's data type and mark required or deprecated fields.
  • Bulk controls let you select all fields or reset the selection to the dataset defaults.
  • Ingestion filters let you ingest all events or only events that match your conditions.

These controls are available when you add a dataset or select Actions > Edit for an enabled dataset.

For more information, refer to Configure fields and filters.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

APO cacht Crawler- und Bot-Traffic wieder

Eine Regression wurde behoben, durch die Automatic Platform Optimization manche HTML-Requests ohne expliziten Accept: text/html-Header nicht mehr cachte, und ein dafür eingerichteter Transform-Rule-Workaround kann entfernt werden.

We fixed a regression where Automatic Platform Optimization (APO) stopped caching some HTML requests that did not send an explicit Accept: text/html header — commonly crawlers, bots, and uptime monitors. These requests were being served from your origin (cf-cache-status: DYNAMIC) instead of the cache.

APO now caches these requests again. No action is needed. If you added a Transform Rule to set Accept: text/html as a workaround, you can remove it.

For details on how APO decides what to cache, refer to About APO.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

API Shield: Höhere Limits für JWT-Validierungskonfigurationen

Die JWT-Validierung in API Shield unterstützt nun standardmäßig 32 Token-Konfigurationen pro Zone mit jeweils bis zu 16 Schlüsseln.

API Shield JSON Web Token validation now supports 32 token configurations per zone by default. Each token configuration can contain up to 16 keys.

These increased limits support more JWT configurations and provide additional capacity for key rotation.

Refer to Configure JWT validation via the API for configuration details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Service-Token-Secrets in scanbarem Format

Cloudflare Access Service-Token-Client-Secrets, die ab dem 26. August 2026 erstellt werden, verwenden das Format cfast_ mit Präfix und Prüfsumme, damit Secret-Scanning-Tools sie leichter erkennen, während bestehende Secrets weiter funktionieren.

Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to identify with fewer false positives.

Existing service token secrets continue to work and do not require rotation. Both formats use the same Client ID and the same CF-Access-Client-Id and CF-Access-Client-Secret authentication headers.

For more information, refer to Service tokens.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Search: Neue Workers-AI-Modelle für die Textgenerierung

AI Search unterstützt sechs weitere Workers-AI-Modelle für die Textgenerierung, darunter DeepSeek V4, gpt-oss, Qwen und Kimi, ohne zusätzlichen Provider-Key.

AI Search now supports six additional Workers AI models for text generation:

Model

Context window (tokens)

@cf/deepseek-ai/deepseek-v4-flash-0731

1,048,576

@cf/deepseek-ai/deepseek-v4-pro-0813

1,048,576

@cf/openai/gpt-oss-120b

128,000

@cf/openai/gpt-oss-20b

128,000

@cf/qwen/qwen3.8-27b

262,144

@cf/moonshotai/kimi-k2.7-code

262,144

These models run on Workers AI, so they do not require an additional provider key. Select a model when creating or updating an AI Search instance in the dashboard or through the API.

For the full list of supported models, refer to Supported models.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Flagship: App-spezifische API-Tokens erstellen

Für Flagship lassen sich app-spezifische API-Tokens mit den Berechtigungen Evaluate, Read oder Write erstellen, die nur Zugriff auf ausgewählte Apps statt auf den ganzen Account gewähren.

You can now create app-scoped API tokens for Flagship. These tokens grant access only to the Flagship apps you select, instead of every app in the account.

When you create a custom token, open the resource dropdown (it defaults to Entire Account) and select Specified Flagship apps. Then choose the app and a Flagship App permission: Evaluate, Read, or Write. Account-wide Flagship Evaluate, Read, and Write permissions still exist when you need access to every app.

Use app-scoped tokens in trusted server-side environments, such as Wrangler, CI, or a backend service that should only touch one app.

To create a token, refer to API tokens or open the app-scoped token form ↗︎ in the dashboard.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Z.ai GLM-5.3 Flash jetzt auf Workers AI verfügbar

Z.ais multimodales Modell @cf/zai-org/glm-5.3-flash ist auf Workers AI verfügbar und erfordert den Workers Paid Plan oder vorausbezahlte AI-Gateway-Credits.

@cf/zai-org/glm-5.3-flash is now available on Workers AI. It is the first natively multimodal model in the GLM-5 series, built on a Mixture-of-Experts architecture with 320B total parameters and 18B active per token.

GLM-5.3 Flash is the first GLM-family model on Workers AI to support multimodal inputs. It outperforms GLM-5.2 across benchmarks and real-world workloads at a lower price, while approaching Claude Opus 4.8 on coding and agentic benchmarks.

GLM-5.3 Flash requires the Workers Paid plan or prepaid AI Gateway credits.

Use GLM-5.3 Flash through the Workers AI binding (env.AI.run()), the REST API, the OpenAI-compatible endpoint, or AI Gateway.

For more information, refer to the GLM-5.3 Flash model page and pricing.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Log-Explorer-Datasets löschen

Account- und Zone-Datasets im Log Explorer lassen sich jetzt über Dashboard oder API dauerhaft löschen, wobei der standardmäßig aktive Löschschutz zuvor deaktiviert werden muss und das Löschen unumkehrbar und asynchron abläuft.

Log Explorer

Cloudflare Log Explorer customers can now permanently delete account and zone datasets from the Cloudflare dashboard or API.

Deletion protection is enabled by default to prevent accidental data loss. In the dashboard, go to Manage datasets, disable deletion protection for the dataset, select Delete, and enter the dataset name to confirm.

To delete a dataset through the API, first set deletion_protection to false with the Update an account or zone dataset method. Then use the Delete an account or zone dataset method.

Dataset deletion is irreversible and runs asynchronously. You cannot recreate the same dataset while deletion is in progress.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Radar Researcher mit mehr Quellen und URL-Scanner-Erklärungen

Radar Researcher verlinkt in Antworten jetzt auf Radar-Seiten, Berichte und Blogbeiträge, erklärt URL-Scanner-Berichte per „Explain with AI“ und öffnet geteilte Unterhaltungen im Vollbild.

Radar

Cloudflare Radar expands the Radar Researcher ↗︎ beta with richer sources and new ways to investigate Internet data.

Connected insights

Radar Researcher responses can now link to relevant Radar pages, reports, and Cloudflare Blog posts.

Radar Researcher response linking to the IP Address Information and Network Quality Test pages

URL Scanner report explanations

Select Explain with AI on a URL Scanner report ↗︎ to have Radar Researcher explain its findings and answer follow-up questions about the scanned site.

Radar Researcher explaining findings from an example.com URL Scanner report

Improved shared sessions

Shared conversations now open in fullscreen, while the share URL remains available until you close the panel or start a new conversation.

Open Radar Researcher ↗︎ to explore these improvements.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-08-26: Next.js RCE und Image Optimizer

Die bestehende Next.js-RCE-Regel erkennt nun CVE-2026-75604 und eine neue Block-Regel schützt vor RCE im Next.js Image Optimizer über manipulierte AVIF-Bilder.

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Key Findings

  • CVE-2026-75604 affects Windows-hosted Next.js applications using both the Pages Router and App Router without Cache Components and can lead to unauthenticated remote code execution.

  • GHSA-2xp9-vwfh-vxw4 affects the Next.js Image Optimizer and can lead to unauthenticated remote code execution when it optimizes an attacker-controlled AVIF image.

Impact

Next.js recommends updating to version 16.3.3 or 15.5.24 to address these vulnerabilities.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...2ca6cce3

N/A

Next.js - Remote Code Execution - CVE:CVE-2026-75604

Block

N/A

Rule metadata description refined. Detection unchanged.

Cloudflare Managed Ruleset

...80256efe

N/A

Next.js - Image Optimizer Remote Code Execution via Crafted AVIF

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Radar Researcher: mehr Quellen und URL-Scanner-Erklärungen

Die Radar-Researcher-Beta verlinkt Antworten nun auf relevante Radar-Seiten, Berichte und Blogbeiträge, erklärt URL-Scanner-Berichte per „Explain with AI“ und öffnet geteilte Unterhaltungen im Vollbild.

Radar

Cloudflare Radar expands the Radar Researcher ↗︎ beta with richer sources and new ways to investigate Internet data.

Connected insights

Radar Researcher responses can now link to relevant Radar pages, reports, and Cloudflare Blog posts.

Radar Researcher response linking to the IP Address Information and Network Quality Test pages

URL Scanner report explanations

Select Explain with AI on a URL Scanner report ↗︎ to have Radar Researcher explain its findings and answer follow-up questions about the scanned site.

Radar Researcher explaining findings from an example.com URL Scanner report

Improved shared sessions

Shared conversations now open in fullscreen, while the share URL remains available until you close the panel or start a new conversation.

Open Radar Researcher ↗︎ to explore these improvements.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Log Explorer-Datasets löschen

Account- und Zone-Datasets in Log Explorer können nun im Dashboard oder per API dauerhaft gelöscht werden, sofern der standardmäßig aktive Löschschutz zuvor deaktiviert wurde.

Cloudflare Log Explorer customers can now permanently delete account and zone datasets from the Cloudflare dashboard or API.

Deletion protection is enabled by default to prevent accidental data loss. In the dashboard, go to Manage datasets, disable deletion protection for the dataset, select Delete, and enter the dataset name to confirm.

To delete a dataset through the API, first set deletion_protection to false with the Update an account or zone dataset method. Then use the Delete an account or zone dataset method.

Dataset deletion is irreversible and runs asynchronously. You cannot recreate the same dataset while deletion is in progress.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Azure Functions-basierter Microsoft Sentinel-Connector wird eingestellt

Enterprise-Kunden müssen bis zum 14.09.2026 vom Azure Functions-basierten Microsoft Sentinel-Connector auf den Cloudflare for Microsoft Sentinel CCF-Connector migrieren, da Microsoft die Azure Monitor HTTP Data Collector API abschaltet.

Cloudflare Enterprise customers using the Azure Functions-based Microsoft Sentinel connector ↗︎ must migrate to the Cloudflare for Microsoft Sentinel Codeless Connector Framework (CCF) connector ↗︎ by 2026-09-14.

Microsoft is deprecating the Azure Monitor HTTP Data Collector API. Support for the API ends on 2026-09-14. As a result, Cloudflare will no longer maintain the Azure Functions-based connector after that date.

To migrate, follow the Microsoft Sentinel integration setup guide.

Additional resources

For more information, refer to Microsoft's Azure Monitor HTTP Data Collector API deprecation notice ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Übergangsfristen bei der Rotation von Service Tokens

Administratoren können bei der Rotation eines Access-Service-Token-Secrets nun eine Übergangsfrist von einer Stunde bis 30 Tagen wählen, in der beide Secrets gültig bleiben.

Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication.

The dashboard offers grace periods from one hour to 30 days. Administrators can also revoke the previous secret immediately. The API accepts an RFC 3339 expiration time for custom rotation schedules.

For configuration instructions, refer to Rotate service token secrets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Service Tokens vorübergehend deaktivieren

Access-Administratoren können Service Tokens jetzt vorübergehend deaktivieren, ohne sie zu löschen, sodass ein deaktiviertes Token sich nicht authentifizieren kann, seine Konfiguration aber erhalten bleibt.

Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later.

Turning off a token also stops any previous secret in an active rotation grace period. Use this control to contain suspected credential exposure or pause an automated service.

For configuration instructions, refer to Turn a service token on or off.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

MCP-Server-Portale unterstützen MCP-Spezifikation 2026-07-28

MCP server portals unterstützen die zustandslose MCP-Spezifikation 2026-07-28 für Client- und Upstream-Verbindungen und greifen bei Bedarf automatisch auf den 2025-Handshake zurück.

MCP server portals support the stateless MCP 2026-07-28 specification for client and upstream server connections.

The portal's /mcp endpoint automatically accepts stateless MCP 2026-07-28 requests and earlier 2025 Streamable HTTP clients. When the portal connects to an upstream Streamable HTTP server, it checks for MCP 2026-07-28 support and falls back to the 2025 handshake when needed. Client and upstream protocol selection are independent, so clients and servers can upgrade separately without portal configuration changes.

SSE connections continue to use the legacy protocol. For details, refer to MCP server portal transport and protocol compatibility.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Search: Größere benutzerdefinierte Metadatenwerte speichern

AI Search erlaubt größere benutzerdefinierte Metadatenwerte innerhalb einer gemeinsamen Metadatengrenze von 10 KiB pro Vektor.

AI Search supports larger custom metadata values within a shared 10 KiB metadata envelope for each vector. The envelope includes AI Search system metadata and JSON overhead, so it is not a per-field limit. The first 64 UTF-8 bytes of each indexed string remain filterable.

For details, refer to Metadata attributes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Durable Objects: Alarm-Wiederholungen bei ctx.abort() verhindern

Mit ctx.abort() kann über die Option { retryAlarm: false } verhindert werden, dass ein unterbrochener Durable-Object-Alarm erneut ausgeführt wird.

By default, an alarm interrupted by ctx.abort() retries after the Durable Object resets. Pass { retryAlarm: false } when the alarm should stop instead:

src/index.jsjs

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm() {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

src/index.tsts

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm(): Promise<void> {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

For example, an alarm that deletes its storage can use this option to avoid repeating the cleanup or re-running the Durable Object constructor.

Alarms can run concurrently with other requests to the same Durable Object. If another request calls ctx.abort() while an alarm is running, the retryAlarm option on that call also controls whether the alarm retries.

The default retry prevents an unrelated request from permanently canceling the alarm. Set retryAlarm: false on every abort path that should stop an in-progress alarm, not only on calls from the alarm handler. Existing calls to ctx.abort() keep retrying alarms.

For local development, retryAlarm requires Wrangler 4.126.0 or later.

For more information, refer to ctx.abort().

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Alarm-Wiederholungen bei Durable Objects mit ctx.abort() verhindern

Mit ctx.abort() und der Option { retryAlarm: false } lässt sich verhindern, dass ein unterbrochener Durable-Object-Alarm erneut ausgeführt wird.

Durable Objects

By default, an alarm interrupted by ctx.abort() retries after the Durable Object resets. Pass { retryAlarm: false } when the alarm should stop instead:

src/index.jsjs

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm() {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

src/index.tsts

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm(): Promise<void> {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

For example, an alarm that deletes its storage can use this option to avoid repeating the cleanup or re-running the Durable Object constructor.

Alarms can run concurrently with other requests to the same Durable Object. If another request calls ctx.abort() while an alarm is running, the retryAlarm option on that call also controls whether the alarm retries.

The default retry prevents an unrelated request from permanently canceling the alarm. Set retryAlarm: false on every abort path that should stop an in-progress alarm, not only on calls from the alarm handler. Existing calls to ctx.abort() keep retrying alarms.

Originalquelle(öffnet in neuem Tab)Problem melden