Zum Inhalt springen

Cloudflare Release Notes

1.135 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

@cloudflare/codemods 0.4.1: Analytics-Bindings und Wrangler-Update

@cloudflare/codemods 0.4.1 berücksichtigt bindings.analytics() anstelle von analyticsSQL(), nutzt bei cf migrate das Standardverhalten der Typgenerierung und aktualisiert Wrangler-Abhängigkeiten auf eine von cf dev unterstützte Version.

Patch Changes

  • #16016 f025bbf Thanks @Ankcorn! - Add bindings.analytics() as the preferred name for Analytics SQL bindings and deprecate bindings.analyticsSQL().

  • #15991 b4f6054 Thanks @NuroDev! - Use the default type generation behavior in projects migrated by cf migrate.

    Wrangler projects without dev.generate_types: false no longer get a wrangler.config.ts solely for a redundant type setting. An explicit opt-out still emits types.generate: false, and other Wrangler tooling still produces a config when needed.

  • #15946 1d38b36 Thanks @NuroDev! - Upgrade Wrangler dependencies to a version supported by cf dev when Wrangler-to-cf migration generates wrangler.config.ts. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

miniflare 5.20261006.0-alpha: assets.base_path und Flagship-Flags

miniflare 5.20261006.0-alpha unterstützt assets.base_path für Workers Assets und ermöglicht in der Local Explorer die Verwaltung lokaler Flagship-Flags.

Minor Changes

  • #15998 b75421f Thanks @dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }
    

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

  • #15330 f8cdcb9 Thanks @akshitsinha! - Manage local Flagship flags in Local Explorer …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

DNS: Warnung bei Annäherung an das Kontingent für DNS-Einträge

Die Seite für DNS-Einträge im Cloudflare-Dashboard zeigt nun eine Warnung an, sobald 85 % des geltenden DNS records quota (je Zone oder kontoweit) verbraucht sind.

The DNS records page in the Cloudflare dashboard now shows a warning once you have used 85% of your DNS records quota.

The warning reflects the quota that applies to you. If your zone has its own quota, the warning shows that zone's usage. If your account uses an account-level DNS records quota, the warning shows your usage across all zones in the account.

Warning on the DNS records page showing that a domain has used 86% of its DNS record limit

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-10-06: Schutz vor F5 BIG-IP CVE-2026-94127

Neue Erkennung für den Heap-Overflow CVE-2026-94127 in F5 BIG-IP (Block), die Beta-Regel „Command Injection - Generic 8 - uri“ wird in die Originalregel überführt und die Next.js-Cache-Poisoning-Beschreibung wurde nur in den Metadaten präzisiert.

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...a056caff

N/A

Command Injection - Generic 8 - uri - Beta

Log

Block

This rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).

Cloudflare Managed Ruleset

...7206c737

N/A

F5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...549f7356

N/A

Next.js - Cache Poisoning - CVE:CVE-2026-94543

Block

Block

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Geplante Änderung für 2026-10-12

Die Regel „Generic Rules - Template Injection - 2 - Beta“ wird zum 2026-10-12 deaktiviert und in die Originalregel „Generic Rules - Template Injection - 2“ überführt.

Announcement Date

Release Date

Release Behavior

Legacy Rule ID

Rule ID

Description

Comments

2026-10-06

2026-10-12

Disable

N/A

...02751ef3

Generic Rules - Template Injection - 2 - Beta

This rule will be merged into the original rule "Generic Rules - Template Injection - 2" (ID: ...d3ed0123).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

BGP über IPsec- und GRE-Tunnel jetzt allgemein verfügbar

BGP-Peering über IPsec- und GRE-Tunnel ist für Cloudflare WAN und Magic Transit allgemein verfügbar und für Produktivumgebungen nutzbar, sodass Routen dynamisch statt über manuell gepflegte statische Routen ausgetauscht werden.

BGP peering over IPsec and GRE tunnels is generally available for Cloudflare WAN and Magic Transit. You can use it for production workloads.

BGP peering exchanges routes dynamically between your devices and your Cloudflare virtual network routing table. You no longer need to update static routes manually as your network changes.

BGP over IPsec and GRE tunnels is available to all accounts that use Unified Routing. No enablement is required. BGP over CNI remains in closed beta.

For configuration details, refer to:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Benutzerdefinierte Finding-Typen für organisationsspezifische Risiken

Cloudflare CASB unterstützt jetzt benutzerdefinierte Finding-Typen, für die sich eigene Erkennungslogik in Rego schreiben und auf bestimmte Anbieter, Asset-Klassen und Integrationen eingrenzen lässt.

Cloudflare CASB now supports custom finding types, giving security teams full control over the security conditions CASB detects across their SaaS and cloud integrations.

In addition to CASB's library of standard finding types, you can now write your own detection logic using Rego ↗︎, the open-source policy language from Open Policy Agent (OPA). Use custom finding types to match your organization's own thresholds and exceptions, such as flagging admin accounts without two-factor authentication, and get higher-confidence findings to act on.

Create a custom finding type with a name, severity, scope, and Rego detection logic

Key capabilities

  • Write your own detection logic — Define exactly what CASB flags using Rego expressions evaluated against asset data from your connected integrations.
  • Target any supported provider and asset class — Scope a custom finding type to a provider (such as Google Workspace or Microsoft 365) and asset class (such as users, files, or groups), and apply it to all integrations for that provider or a selected subset. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

AI Gateway vereinheitlicht Fehlerantworten bei abgelehnten Provider-Zugangsdaten

Die AI Gateway REST API liefert für POST /ai/run bei abgelehnten Provider-Zugangsdaten nun einheitlich HTTP 401 mit Fehlercode 2009 (bei Unified Billing HTTP 503), und Google Vertex wird dabei nicht mehr wiederholt angefragt.

AI Gateway

AI Gateway's REST API now returns consistent responses when an AI provider rejects credentials. The change applies to POST /ai/run ↗︎.

Scenario Previous AI Gateway response New AI Gateway response
ElevenLabs Provider-specific UserCredentialsError with HTTP 403 HTTP 401 with error code 2009
Google Vertex HTTP 500 for rejected credentials, with upstream retries HTTP 401 with error code 2009; the request fails without retrying the provider
All other providers HTTP 402 or another provider-specific status for rejected credentials HTTP 401 with error code 2009
When using Unified Billing, the provider rejects the credentials Provider-specific authentication error HTTP 503

Update applications that handle AI Gateway REST API errors to treat HTTP 401 as an invalid or rejected provider credential.

For details about providing provider credentials, refer to Bring your own provider keys.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Network Security von Cloudflare

BGP über IPsec- und GRE-Tunnel allgemein verfügbar

BGP-Peering über IPsec- und GRE-Tunnel ist für Cloudflare WAN und Magic Transit allgemein verfügbar und für Produktivlasten nutzbar, sodass Routen dynamisch ausgetauscht werden und statische Routen nicht mehr manuell angepasst werden müssen.

BGP peering over IPsec and GRE tunnels is generally available for Cloudflare WAN and Magic Transit. You can use it for production workloads.

BGP peering exchanges routes dynamically between your devices and your Cloudflare virtual network routing table. You no longer need to update static routes manually as your network changes.

BGP over IPsec and GRE tunnels is available to all accounts that use Unified Routing. No enablement is required. BGP over CNI remains in closed beta.

For configuration details, refer to:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

AI Gateway von Cloudflare

Web Search API als Beta über AI Gateway verfügbar

Die Web Search API ist als Beta verfügbar und ermöglicht KI-Agenten und Anwendungen die Websuche über Ceramic.ai, Exa oder Linkup, abgewickelt über AI Gateway ohne Aufschlag auf die Listenpreise der Provider.

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff.

At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all have committed to Cloudflare's verified bot crawling standards.

Web Search API runs through AI Gateway, so search requests appear in your gateway logs and are billed to your AI Gateway credits at each provider's list API price, with no additional markup. You can also bring your own provider API key.

Call Web Search API with the REST API:

curl https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/ai/websearch/ \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "query": "What are some fun things to do in Salt Lake City as fall approaches?",
    "provider": "ceramic",
    "limit": 5,
    "options": { "gateway": { "id": "default" } }
  }'

Or from a Worker with the AI binding:

const response = await env.AI.websearch({
	gatewayId: "default", …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Neue Einstellung für strikte Service-Token-Authentifizierung

Die neue Einstellung „strict service token authentication“ sorgt dafür, dass Access bei Anfragen mit Service Tokens einheitlich 401/403 statt 302 zurückgibt, nur Service-Auth-Policies berücksichtigt und kein CF_Authorization-Cookie ausstellt, und ist für ab dem 5. Oktober 2026 erstellte Organisationen standardmäßig aktiv.

The strict service token authentication setting applies consistent behavior to requests made with service tokens. When the setting is on for a Zero Trust organization, Access handles requests with service token headers as follows:

  • If authentication or authorization fails, Access always returns 401 or 403 instead of redirecting the client to the login page with 302.
  • Only Service Auth policies can authorize the request. Access ignores Allow policies and any CF_Authorization cookie sent with the request.
  • Access does not return a CF_Authorization cookie to the client after successful authentication. Subsequent requests should continue to use service token headers.
  • Failed requests for recognized service tokens appear in Access authentication logs.

Zero Trust organizations created on or after October 5, 2026 have strict service token authentication turned on by default and cannot turn it off. Cloudflare recommends that existing organizations turn it on as well.

Organizations created before October 5, 2026 can configure the setting in the dashboard or through the API.

  1. In the Cloudflare dashboard ↗︎, go to Zero Trust > Access controls > Access settings.

    Go to Access settings ↗ …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Web Search API als Beta eingeführt

Die Web Search API ist als Beta verfügbar und lässt KI-Agenten und Anwendungen über Ceramic.ai, Exa oder Linkup im Internet suchen, abgerechnet über AI Gateway-Guthaben ohne Aufschlag.

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff.

At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all have committed to Cloudflare's verified bot crawling standards.

Web Search API runs through AI Gateway, so search requests appear in your gateway logs and are billed to your AI Gateway credits at each provider's list API price, with no additional markup. You can also bring your own provider API key.

Call Web Search API with the REST API:

curl https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/ai/websearch/ \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "query": "What are some fun things to do in Salt Lake City as fall approaches?",
    "provider": "ceramic",
    "limit": 5,
    "options": { "gateway": { "id": "default" } }
  }'

Or from a Worker with the AI binding:

const response = await env.AI.websearch({
	gatewayId: "default", …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Agents SDK: Pi Durable Harness mit der Klasse PiHarness auf Cloudflare

Das Agents SDK unterstützt nun mit der neuen Klasse PiHarness die Pi-Harness (Pi 1.0 und Pi Durable), sodass langlaufende Agenten ihre Arbeit auch bei Unterbrechungen dauerhaft sichern.

The Agents SDK now provides first-class support for building agents using the Pi harness. You can build long-running agents using the combination of Pi 1.0 ↗︎, Pi Durable ↗︎, and the new PiHarness class that the Cloudflare Agents SDK provides, ensuring your agent's work is durably persisted, even if interrupted mid-turn.

Built with Earendil ↗︎, this integration is our first step toward first-class support for third-party agent harnesses on Cloudflare.

Copy promptPrompt copied!

Deploy to Cloudflare

Beta …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

D1: Jurisdiktion „US“ für Datenbanken verfügbar

D1-Datenbanken lassen sich jetzt mit der Jurisdiktion us erstellen, sodass Daten ausschließlich in den USA verarbeitet und gespeichert werden.

You can create D1 databases with the us jurisdiction. These databases run and persist data within the United States.

Use this option for regional data residency requirements.

To create a database with the us jurisdiction, run:

npx wrangler@latest d1 create db-with-us-jurisdiction --jurisdiction=us

For more information, refer to D1 data location.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers KV: Namespace-Jurisdiktionen allgemein verfügbar

Jurisdiktionen für Workers KV Namespaces (eu, us, fedramp) sind allgemein verfügbar und lassen sich nur beim Erstellen eines Namespace festlegen.

Jurisdictions for Workers KV namespaces are now generally available. When you create a namespace, you can set a jurisdiction to make sure the namespace's data is only durably stored within that region. Jurisdictions can help you comply with data localization regulations such as GDPR or FedRAMP. Supported jurisdictions are eu, us, and fedramp.

A jurisdiction can only be set when a namespace is created, using the Cloudflare dashboard, Wrangler, the cf CLI, or the REST API, and cannot be added or changed afterwards.

npx wrangler@latest kv namespace create <NAMESPACE_NAME> --jurisdiction=eu
cf kv namespaces create --title <NAMESPACE_NAME> --jurisdiction eu
curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/storage/kv/namespaces" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "title": "<NAMESPACE_NAME>",
    "jurisdiction": "eu"
  }'

Workers can still access a namespace restricted to a jurisdiction from anywhere in the world, and KV data can be cached outside the jurisdiction on Cloudflare's network. The jurisdiction only controls where the namespace's data is durably stored.

To learn more, refer to Data location.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

D1-Datenbanken mit US-Jurisdiktion erstellen

D1-Datenbanken lassen sich jetzt mit der Jurisdiktion us erstellen, sodass Daten ausschließlich in den USA laufen und gespeichert werden.

D1

You can create D1 databases with the us jurisdiction. These databases run and persist data within the United States.

Use this option for regional data residency requirements.

To create a database with the us jurisdiction, run:

npx wrangler@latest d1 create db-with-us-jurisdiction --jurisdiction=us

For more information, refer to D1 data location.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Workers KV Namespace-Jurisdiktionen allgemein verfügbar

Jurisdiktionen für Workers KV Namespaces (eu, us, fedramp) sind allgemein verfügbar und können nur beim Erstellen eines Namespace festgelegt werden.

KV

Jurisdictions for Workers KV namespaces are now generally available. When you create a namespace, you can set a jurisdiction to make sure the namespace's data is only durably stored within that region. Jurisdictions can help you comply with data localization regulations such as GDPR or FedRAMP. Supported jurisdictions are eu, us, and fedramp.

A jurisdiction can only be set when a namespace is created, using the Cloudflare dashboard, Wrangler, the cf CLI, or the REST API, and cannot be added or changed afterwards.

npx wrangler@latest kv namespace create <NAMESPACE_NAME> --jurisdiction=eu
cf kv namespaces create --title <NAMESPACE_NAME> --jurisdiction eu
curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/storage/kv/namespaces" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "title": "<NAMESPACE_NAME>",
    "jurisdiction": "eu"
  }'

Workers can still access a namespace restricted to a jurisdiction from anywhere in the world, and KV data can be cached outside the jurisdiction on Cloudflare's network. The jurisdiction only controls where the namespace's data is durably stored.

To learn more, refer to Data location.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

wrangler 4.147.0: Jurisdiktion "us" für Container, LIVE INSTANCES

wrangler 4.147.0 erlaubt "us" als Jurisdiktion für Container-Anwendungen, und wrangler containers list zeigt in der Spalte LIVE INSTANCES nun die tatsächlich aktiven Instanzen an.

Minor Changes

  • #15928 7f57b1c Thanks @ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Patch Changes

  • #15974 7f700ef Thanks @martinezjandrew! - Fix wrangler containers list to report live instances

    The LIVE INSTANCES column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing instances field.

  • #15980 90e6a1b Thanks @martinezjandrew! - Accept Durable Object application IDs in Containers commands …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

create-cloudflare 2.73.2: Unterstützung für SvelteKit 3

create-cloudflare 2.73.2 unterstützt SvelteKit-3-Projekte, indem es den dazu kompatiblen Cloudflare-Adapter nutzt und generierte SvelteKit-Typen beim Hinzufügen von Workers-Typen erhält.

Patch Changes

  • #16017 1bc7269 Thanks @jamesopstad! - Support SvelteKit 3 projects

    Create Svelte projects with the SvelteKit 3-compatible Cloudflare adapter and preserve SvelteKit's generated types when adding Workers types.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

workers-utils 0.46.0: Container-Jurisdiktion "us" erlaubt

@cloudflare/workers-utils 0.46.0 erlaubt constraints.jurisdiction: "us" für Container-Platzierungen neben "eu" und "fedramp".

Minor Changes

  • #15928 7f57b1c Thanks @ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Originalquelle(öffnet in neuem Tab)Problem melden