Zum Inhalt springen

Cloudflare Release Notes

1.616 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Alarm-Wiederholungen bei ctx.abort() verhindern

Mit { retryAlarm: false } bei ctx.abort() lässt sich verhindern, dass ein unterbrochener Alarm in Durable Objects erneut ausgeführt wird, während bestehende Aufrufe weiterhin wiederholen und lokal Wrangler 4.126.0 nötig ist.

By default, an alarm interrupted by ctx.abort() retries after the Durable Object resets. Pass { retryAlarm: false } when the alarm should stop instead:

src/index.jsjs

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm() {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

src/index.tsts

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm(): Promise<void> {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

For example, an alarm that deletes its storage can use this option to avoid repeating the cleanup or re-running the Durable Object constructor.

Alarms can run concurrently with other requests to the same Durable Object. If another request calls ctx.abort() while an alarm is running, the retryAlarm option on that call also controls whether the alarm retries.

The default retry prevents an unrelated request from permanently canceling the alarm. Set retryAlarm: false on every abort path that should stop an in-progress alarm, not only on calls from the alarm handler. Existing calls to ctx.abort() keep retrying alarms.

For local development, retryAlarm requires Wrangler 4.126.0 or later.

For more information, refer to ctx.abort().

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Alarm-Wiederholung bei ctx.abort() in Durable Objects verhindern

Mit der Option { retryAlarm: false } bei ctx.abort() lässt sich verhindern, dass ein unterbrochener Alarm nach dem Zurücksetzen des Durable Objects erneut ausgeführt wird, während bestehende Aufrufe weiterhin Alarme wiederholen.

Durable Objects

By default, an alarm interrupted by ctx.abort() retries after the Durable Object resets. Pass { retryAlarm: false } when the alarm should stop instead:

src/index.jsjs

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm() {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

src/index.tsts

import { DurableObject } from "cloudflare:workers";

export class CleanupTask extends DurableObject {
	async alarm(): Promise<void> {
		await this.ctx.storage.deleteAll();

		this.ctx.abort("Cleanup complete", { retryAlarm: false });
	}
}

For example, an alarm that deletes its storage can use this option to avoid repeating the cleanup or re-running the Durable Object constructor.

Alarms can run concurrently with other requests to the same Durable Object. If another request calls ctx.abort() while an alarm is running, the retryAlarm option on that call also controls whether the alarm retries.

The default retry prevents an unrelated request from permanently canceling the alarm. Set retryAlarm: false on every abort path that should stop an in-progress alarm, not only on calls from the alarm handler. Existing calls to ctx.abort() keep retrying alarms.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

API Shield: Symmetrische Schlüssel für JWT-Validierung

Die JWT-Validierung in API Shield unterstützt jetzt symmetrische Schlüssel mit HS256, HS384 und HS512, die im Dashboard oder per API konfiguriert werden können.

API Shield JSON Web Token validation now supports symmetric keys that use the HS256, HS384, and HS512 algorithms. You can configure HMAC verification keys in the Cloudflare dashboard or with the Cloudflare API.

Cloudflare never stores symmetric credentials in plaintext. API responses do not include the credential.

Refer to Configure JWT validation via the API for supported key formats and credential requirements.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-08-25: Mehrere Regeln auf Block, neue RCE-Regel

Vier Erkennungen (HTTP/2 Request Smuggling und XSS-Event-Handler-Coercion) wechseln von Log auf Block, die Beta-Regel „XSS, HTML Injection - Script Tag“ wird zusammengeführt und eine Generic-Rules-RCE-Regel kommt im Block-Modus hinzu.

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode.

Key Findings

  • Four new detections move from Log to Block: HTTP/2 Request Smuggling - Request Body Anomaly and XSS - JavaScript Event Handler Coercion across Headers, Body, and URI.

  • The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule.

  • A Generic Rules - Remote Code Execution detection is added in Block mode.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...1489d892

N/A

HTTP/2 Request Smuggling - Request Body Anomaly

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...20646260

N/A

XSS - JavaScript Event Handler Coercion - Headers

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...d706d517

N/A

XSS - JavaScript Event Handler Coercion - Body

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...660886c8

N/A

XSS - JavaScript Event Handler Coercion - URI

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...c293b926

N/A

XSS, HTML Injection - Script Tag - Beta

Log

Block

This rule is merged into the original rule "XSS, HTML Injection - Script Tag" (ID: ...7b58420b).

Cloudflare Managed Ruleset

...2ca6cce3

N/A

Generic Rules - Remote Code Execution

N/A

Block …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Virtual Appliance je Hypervisor im Dashboard herunterladen

Beim Registrieren einer Cloudflare One Virtual Appliance lässt sich im Dashboard jetzt der Hypervisor (VMware ESXi, Proxmox oder libvirt/KVM) auswählen und das passende OVA-Image oder Installationsskript direkt herunterladen.

When you register a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs.

Selecting a hypervisor and downloading the Cloudflare One Virtual Appliance from the Connectors page

  • On the Connectors page, select Add an appliance, choose Virtual appliance, then select your hypervisor: VMware ESXi, Proxmox, or libvirt/KVM.
  • Download the OVA image (VMware ESXi) or the install script (Proxmox and libvirt/KVM) for the selected hypervisor.
  • Use View setup guide to open deployment instructions for your platform.

This complements the existing self-serve registration and license key generation in the dashboard.

For details, refer to Configure a Cloudflare One Virtual Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers: Exception-Details in Console-Logs bleiben erhalten

Console-Methoden behalten Exception-Details bei, sodass Logs Name, Meldung und Stack enthalten und Tail Workers ein errorInfo-Array erhalten.

Console methods now preserve exception details in your Worker's logs. When your Worker logs an exception, the corresponding log entry includes the exception name, message, and stack.

For example, your Worker can catch and log an exception:

try {
	throw new Error("Deliberately created exception");
} catch (error) {
	console.error("caught exception:", error);
}
try {
	throw new Error("Deliberately created exception");
} catch (error) {
	console.error("caught exception:", error);
}

If you use Workers Observability, your log is automatically enriched with structured error information. The following example shows how the enriched log appears in the Cloudflare dashboard:

Workers Observability log entry showing a caught exception and its stack trace

The exception's stack trace appears directly in the log message.

If you send telemetry to a Tail Worker, the Tail Worker now receives a log entry with an errorInfo array:

{
	"message": ["Request failed:", "RangeError: Value out of range"],
	"errorInfo": [
		null,
		{
			"name": "RangeError",
			"message": "Value out of range",
			"stack": "RangeError: Value out of range\n    at ..."
		}
	],
	"level": "error", …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

RPKI-ASPA-Pfadvalidierung auf Cloudflare Radar

Radar enthält im Routing-Bereich ein neues ASPA-Validierungstool, das einen eingegebenen BGP-AS_PATH gegen im RPKI veröffentlichte ASPA-Records prüft und das Ergebnis Valid, Invalid oder Unknown liefert.

Radar

Radar adds an ASPA validation tool ↗︎ to its Routing section ↗︎. Enter a BGP AS_PATH and the tool checks it against the Autonomous System Provider Authorization (ASPA) ↗︎ records currently published in the RPKI, returning a verdict of Valid, Invalid, or Unknown. An Invalid verdict means no chain of provider authorizations covers the whole path, which is the signature of a route leak.

Validation follows draft-ietf-sidrops-aspa-verification ↗︎, so verdicts match those produced by validators implementing the same draft. The draft is still a work in progress and not yet an RFC.

Enter a path

Paths are read in BGP wire order: the rightmost AS is the origin, and the leftmost AS is the one closest to the collector or router that observed the route. AS numbers can be separated by spaces, commas, or hyphens, with or without an AS prefix. The full ASPA snapshot is loaded into the browser once, so the verdict, graph, and trace update as the path is edited, with no further requests. A set of example paths covers the interesting cases, including a route leak with an AS0 ASPA, where an AS declares that it has no providers at all. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

RPKI-ASPA-Pfadvalidierung in Cloudflare Radar

Radar bietet im Routing-Bereich ein neues ASPA-Validierungstool, das einen eingegebenen BGP-AS_PATH gegen die im RPKI veröffentlichten ASPA-Einträge prüft und „Valid“, „Invalid“ oder „Unknown“ ausgibt.

Radar

Radar adds an ASPA validation tool ↗︎ to its Routing section ↗︎. Enter a BGP AS_PATH and the tool checks it against the Autonomous System Provider Authorization (ASPA) ↗︎ records currently published in the RPKI, returning a verdict of Valid, Invalid, or Unknown. An Invalid verdict means no chain of provider authorizations covers the whole path, which is the signature of a route leak.

Validation follows draft-ietf-sidrops-aspa-verification ↗︎, so verdicts match those produced by validators implementing the same draft. The draft is still a work in progress and not yet an RFC.

Enter a path

Paths are read in BGP wire order: the rightmost AS is the origin, and the leftmost AS is the one closest to the collector or router that observed the route. AS numbers can be separated by spaces, commas, or hyphens, with or without an AS prefix. The full ASPA snapshot is loaded into the browser once, so the verdict, graph, and trace update as the path is edited, with no further requests. A set of example paths covers the interesting cases, including a route leak with an AS0 ASPA, where an AS declares that it has no providers at all. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

OAuth-Scopes für Wrangler und Cloudflare API MCP Server wählbar

Wrangler und der Cloudflare API MCP Server nutzen optionale OAuth-Scopes, die bei der Autorisierung einzeln gewährt oder abgelehnt werden können.

Wrangler and the Cloudflare API MCP server now use optional OAuth scopes. During authorization, you can choose which optional scopes to grant instead of approving every scope requested by each client.

The consent dialog now includes the option to edit the permissions you grant to Wrangler or the Cloudflare API MCP server:

OAuth consent dialog with an Edit Permissions button

You can then choose which specific permissions to grant:

OAuth permission editor with controls for individual scopes

Required scopes remain selected. Choosing fewer optional scopes limits each tool's access to the permissions needed for your workflow.

If a command or tool call needs a scope that you declined, reauthorize the client and grant that scope.

For more information, refer to wrangler login and Edit optional permissions.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Automatische Behebung von Befunden in Microsoft 365 und Google Workspace

CASB-Remediation-Policies beheben Befunde zur Dateifreigabe in Microsoft 365 und Google Workspace jetzt automatisch und können zusätzlich Webhooks an Ziele wie Slack oder ServiceNow senden.

Cloudflare CASB is an API-based (agentless) tool that continuously scans your SaaS and cloud applications for security misconfigurations and data exposure. You can now use CASB remediation policies to automatically fix a finding or send a webhook the moment CASB detects it, without manual triage.

Remediate Microsoft 365 and Google Workspace findings

A policy can perform a first-party remediation action directly against the SaaS integration API. When a policy triggers, Cloudflare revokes the external sharing configuration without human intervention.

Remediation is currently supported for file-sharing findings in Microsoft 365 and Google Workspace. Support for additional finding types and integrations is coming soon. For the full list of supported finding types, refer to Run remediations in the CASB remediation policies documentation.

Send webhooks

A policy can send posture finding data to Slack, ServiceNow, or any other webhook destination. Webhook actions are supported for all posture finding types across CASB integrations.

A single policy can perform both actions: remediate a finding and send a webhook.

Get started

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Profile mit Test scan prüfen, ohne Traffic durch Gateway

Mit Test scan lassen sich DLP-Profile anhand von eingefügtem Text, Dateien oder HAR-Dateien prüfen, ohne Traffic durch Gateway zu leiten und ohne dass Gateway-Aktivitätslogs entstehen.

Test scan lets you check how Data Loss Prevention (DLP) evaluates sample content before you apply a profile to production traffic. Paste text, upload a file, or upload a HAR file, then select the profiles you want to test.

Test scan results showing matched profiles, detection entries, and match context

Test scan sends content directly to the DLP scanner. Gateway policies are not evaluated, no traffic passes through Gateway, and no Gateway activity logs are created. Results include matched profiles, detection entries, confidence levels, match context, proximity keywords, file metadata, antivirus status, and OCR output.

Test scan is available to all Cloudflare Zero Trust customers. Profile availability depends on your Zero Trust plan.

For more details, refer to the Test scan documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

Web Analytics misst Soft Navigations in SPAs genauer

Cloudflare Web Analytics verbessert die Messung clientseitiger Soft Navigations in Single Page Applications, wodurch sich die gemeldeten Pageviews, Visits und der LCP-Wert verändern können.

Cloudflare Web Analytics (Real User Monitoring) is rolling out accuracy improvements to client-side soft navigations. Update: this update is complete as of 2026-09-04.

This change may alter the volume of reported pageviews and visits in the dashboard and GraphQL API. The reported Largest Contentful Paint (LCP) metric may also fluctuate. The extent of these variances depend on your front-end architecture and visitor traffic patterns.

Single Page Applications (SPAs)—such as websites built with React, Angular, Vue, or Svelte—predominantly use soft navigations. Soft navigations avoid fully unloading the current page and rendering the next one from scratch as visitors navigate.

Any client-side navigation counts as a soft navigation, including navigations intercepted by the Navigation API ↗︎ or triggered by the History API ↗︎. This means a non-SPA website can have soft navigation activity if its implementation uses these APIs.

The main improvement comes from Google Chrome's new Soft Navigation API ↗︎. It natively measures Largest Contentful Paint (LCP) on soft navigations, removing a blind spot in perceived loading speed across pageviews. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Erweiterte 403-Antworten der Cloudflare API

403-Forbidden-Antworten der Cloudflare API enthalten nun ein Feld documentation_url, das auf die Dokumentation des abgelehnten Endpunkts mit den erforderlichen Rollen verweist.

Cloudflare API 403 Forbidden responses now include a documentation_url field that links directly to the API documentation for the endpoint that was denied. This gives developers, administrators, and agents an immediate path to the relevant docs with role information instead of guessing at which role or permission they are missing for that endpoint.

What's New

Enriched 403 error responses: When a Cloudflare API request is denied, the error response now includes a documentation_url field that points to the documentation for that specific endpoint. Contextual 403 responses are now available across nearly all Cloudflare product APIs.

Faster troubleshooting: The linked API docs surface the roles required for each endpoint, making it easier to self-serve access issues.

Better support for tools and agents: Agents can use the \documentation_url` field to immediately fetch the endpoint's documentation from the 403 error response, identify the accepted permissions for the denied action, and use that context to drive third-party approval workflows.`

Example 403 response:

{
  "success": false,
  "errors": [
    {
      "code": 10000,
      "message": "Forbidden",
      "documentation_url": "https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/list"
    }
  ],
  "messages": [],
  "result": null
}

For more info:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Gespeicherte Login-Profile für wiederkehrende Nutzer

Nutzer des Cloudflare Dashboards können nach der Anmeldung bis zu fünf Login-Profile pro Gerät speichern, die auf der Login-Seite die Anmeldung per Passwort, SSO oder Social Login beschleunigen.

Cloudflare Dashboard users can now save login profiles on a device for faster sign-in on future visits.

Saved login profiles for returning users

What's New

Save login profiles on a device: After a successful sign-in, users can choose to save a login profile on that device. Saved profiles store the email address, login method, and last-used profile locally in the browser.

Faster sign-in for returning users: Saved profiles appear directly on the login page. Selecting one can prefill the email field for password logins or resume the associated SSO or social login flow.

Up to five login profiles can be saved per device, and saved profiles can be removed from the profile list at any time.

For more info:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Verbesserte SCIM 2.0-Gruppensynchronisierung

Dashboard SCIM unterstützt nun das Ersetzen von Gruppen per HTTP PUT gemäß RFC 7644, sodass Identity Provider den vollständigen Gruppenzustand in einer Anfrage synchronisieren können.

Dashboard SCIM now supports replacing groups using HTTP PUT, as defined by RFC 7644 section 3.5.1 ↗︎. This allows identity providers to synchronize a group's full state, including its display name, external ID, and members, in a single request.

What's New

Group replacement via PUT: Full-state group synchronization improves compatibility with identity providers that use replacement semantics and helps keep Cloudflare groups aligned with their source identity provider.

Note

SCIM provisioning for the Cloudflare dashboard is available to Enterprise customers. You must be a Super Administrator to complete the initial setup.

For more information:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Browser Run: Mehr gleichzeitige Headless-Browser im Paid Plan

Im Workers Paid Plan erhöhen sich die Standardlimits von Browser Run auf 200 gleichzeitige Browser, 3 neue Instanzen pro Sekunde und 30 Quick-Actions-Anfragen pro Sekunde.

Browser Run lets you automate headless browsers on Cloudflare's global network. Run full browser sessions for interactive workflows, or use Quick Actions for one-request tasks such as screenshots, PDFs, and capturing page content.

If you are on the Workers Paid plan, your default limits are now higher:

Limit

Previous

New

Concurrent browsers

120

200

New browser instances / second

1

3

Quick Actions requests / second

10

30

You can now run hundreds of browser sessions in parallel, launch new browsers faster, and process three times as many Quick Actions per second. These published limits are defaults, not maximums. If your workload needs more more concurrent browsers, request higher limits ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Containers: FUSE in der lokalen Entwicklung nutzen

Miniflare gewährt lokalen Containers automatisch die für FUSE nötigen Docker-Privilegien, sofern der Docker-Daemon in einer VM läuft oder bei rootless Docker unter Linux /dev/fuse verfügbar ist.

Miniflare now automatically grants local Containers the Docker privileges required for Filesystem in Userspace (FUSE). This applies to wrangler dev, the Cloudflare Vite plugin, and direct Miniflare use.

Miniflare grants these privileges when the local Docker daemon runs inside a virtual machine (VM). This includes Docker engines on macOS and through Windows Subsystem for Linux (WSL). On Linux, Miniflare grants the privileges for local rootless Docker when /dev/fuse is available.

Rootful Docker on Linux does not support FUSE by default during local development. Miniflare does not grant FUSE privileges when the Docker daemon does not meet these conditions or cannot be inspected.

For requirements and troubleshooting, refer to FUSE support during local development. For a complete example, refer to Mount R2 buckets with FUSE.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Durable Objects: Deployments im Dashboard einsehen

Durable-Object-Namespaces haben im Cloudflare-Dashboard einen schreibgeschützten Deployments-Tab mit den aktiven Versionen, der Traffic-Aufteilung und Metriken je Version.

Durable Object namespaces now have a Deployments tab in the Cloudflare dashboard, showing the versions of the backing Worker that are currently live and the traffic split between them.

The Deployments tab for a Durable Object namespace, showing two versions with their traffic %, requests/sec, error rate, and median wall time Go to Durable Objects ↗

A Durable Object namespace is backed by a Worker script, so its deployments are the same as that Worker's deployments. Previously, checking on a gradual deployment in progress for a Durable Object meant navigating to the backing Worker. The new tab surfaces that information directly on the namespace, alongside the metrics that matter for it: requests, error rate, and wall time per version.

The tab is read-only — promoting, rolling back, or splitting traffic on a deployment is still managed from the backing Worker's Deployments tab.

Actual vs. configured traffic split

…

Originalquelle(öffnet in neuem Tab)Problem melden