Zum Inhalt springen

Cloudflare Release Notes

1.615 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Durable-Object-Logs und -Traces nach Instanz-ID filtern

Workers Logs und OpenTelemetry-Spans für Durable-Object-Anfragen enthalten jetzt die Instanz-ID, sodass sich Logs und Traces über $workers.durableObjectId bzw. cloudflare.durable_object.id nach einzelnen Instanzen filtern lassen.

Workers Logs and OpenTelemetry spans for Durable Object requests include the Durable Object instance ID.

Use $workers.durableObjectId to filter logs for a specific instance. Root and child spans include the same ID in cloudflare.durable_object.id.

Query Builder filtering traces by Durable Object instance ID

Use these fields to isolate a specific instance and correlate its logs and traces.

For more information, refer to Durable Objects metrics and analytics and Workers tracing spans and attributes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers Builds überspringt überholte wartende Builds

Workers Builds überspringt einen wartenden Build automatisch, wenn für denselben Build-Trigger ein neuerer Build in der Warteschlange steht.

Workers Builds now automatically skips a queued build when a newer build for the same build trigger is also queued.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Sippy unterstützt Azure Blob Storage und S3-kompatible Anbieter

Sippy kann jetzt zusätzlich zu Amazon S3 und Google Cloud Storage auch Daten aus Azure Blob Storage und beliebigen S3-kompatiblen Anbietern schrittweise nach Cloudflare R2 migrieren.

R2

Sippy can now incrementally migrate data from Azure Blob Storage and any S3-compatible object storage provider to Cloudflare R2, in addition to Amazon S3 and Google Cloud Storage. Sippy copies objects to R2 as your application requests them, so you can start serving data from R2 without first moving your entire dataset or paying migration-specific egress fees.

Enable Sippy

Run the following command and follow the prompts to select and configure your source storage provider:

npx wrangler r2 bucket sippy enable "<BUCKET_NAME>"

For Azure Blob Storage, provide your storage account name, container name, and either an account key or a shared access signature (SAS) token with read and list permissions. For an S3-compatible provider, provide the S3 API endpoint URL and read-only Access Key ID and Secret Access Key.

Azure Blob Storage source configuration in the R2 dashboard

After you enable Sippy, requests for objects that are not yet in R2 are served from your source bucket and copied to R2. Subsequent requests for those objects are served from R2. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Agents-SDK-Pakete unterstützen AI SDK v6 und v7

Die Pakete agents, @cloudflare/ai-chat, @cloudflare/codemode und @cloudflare/think unterstützen jetzt AI SDK v6 und v7, wobei bestehende Anwendungen auf v6 bleiben können.

The agents, @cloudflare/ai-chat, @cloudflare/codemode, and @cloudflare/think packages now support AI SDK v6 and v7. Existing applications can remain on v6 when updating these packages. Applications can also adopt v7 without changing the Cloudflare Agents APIs they use.

The supported peer ranges are ai@^6 || ^7 and @ai-sdk/react@^3 || ^4. Use matching major versions: pair AI SDK v6 with @ai-sdk/react v3, or pair AI SDK v7 with @ai-sdk/react v4.

To install the latest packages with AI SDK v7:

npmyarnpnpmbun

npm i agents@latest @cloudflare/ai-chat@latest @cloudflare/codemode@latest @cloudflare/think@latest ai@^7 @ai-sdk/react@^4
yarn add agents@latest @cloudflare/ai-chat@latest @cloudflare/codemode@latest @cloudflare/think@latest ai@^7 @ai-sdk/react@^4
pnpm add agents@latest @cloudflare/ai-chat@latest @cloudflare/codemode@latest @cloudflare/think@latest ai@^7 @ai-sdk/react@^4
bun add agents@latest @cloudflare/ai-chat@latest @cloudflare/codemode@latest @cloudflare/think@latest ai@^7 @ai-sdk/react@^4

Think normalizes streaming, tool completion events, and telemetry across both AI SDK versions. Existing v6 applications do not need to migrate these integrations before updating Think.

For setup and usage details, refer to the Think documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Agents SDK: weniger MCP-Schema-Konvertierung, includeMcpTools und Code-Mode-Host-APIs

Das Agents SDK konvertiert MCP-Schemas seltener erneut, Think erhält die Option includeMcpTools zum Abschalten der automatischen MCP-Tool-Bereitstellung, und das Code Mode SDK bietet direkte Host-APIs.

This release reduces repeated MCP schema conversion and adds an opt-out for Think's automatic MCP tool exposure. It also lets non-AI-SDK hosts invoke the durable Code Mode runtime directly.

Control direct MCP tool exposure in Think

Agents SDK MCP clients now reuse converted input and output schemas while a live connection keeps the same tool catalog. This avoids converting every MCP JSON Schema to Zod again for each model turn.

@cloudflare/think also adds includeMcpTools. Set it to false when you expose MCP tools through Code Mode or another mechanism outside Think's automatic tool set:

import { Think } from "@cloudflare/think";

export class MyAgent extends Think {
	includeMcpTools = false;
	waitForMcpConnections = true;
}
import { Think } from "@cloudflare/think";

export class MyAgent extends Think<Env> {
	includeMcpTools = false;
	waitForMcpConnections = true;
}

This setting skips Think's automatic getAITools() call. MCP registration, restoration, discovery, raw catalog access, direct calls, and Code Mode connectors continue to work.

Use listTools() when you only need the raw MCP catalog. For connector setup, refer to Use MCP tools with Code Mode.

Invoke the Code Mode runtime without the AI SDK …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.6.880.0

Der Cloudflare One Client für Windows 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.6.880.0

Der Cloudflare One Client für macOS 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.6.880.0

Der Cloudflare One Client für Linux 2026.6.880.0 behebt eine Regression mit stark erhöhten DNS-over-TCP-Anfragen, indem Fallback-DNS-Anfragen zuerst per UDP und nur bei gekürzter Antwort per TCP gesendet werden.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Devin auf Cloudflare ausführen mit Devin Outposts

Devin-Agenten können über Devin Outposts auf Cloudflare laufen, wobei jede Session in einer eigenen, durch Cloudflare Containers gestützten Sandbox isoliert ist.

Devin Outposts ↗︎ lets you run Devin agents on Cloudflare. Each Devin session runs in its own isolated sandbox backed by Cloudflare Containers, so agents can execute code and use development tooling in an isolated environment.

Use Devin Outposts when you want Devin sessions to run on Cloudflare managed infrastructure, with each session isolated from the others.

Devin interface showing Cloudflare selected as an Outposts virtual environment

To get started, refer to Run Devin on Cloudflare using Devin Outposts.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

Schnellere und sicherere TLS-Handshakes zu Origins per Automatic key exchange

Automatic key exchange sagt für TLS 1.3 zu Origins den bevorzugten Algorithmus voraus, spart so eine Netzwerk-Runde, bevorzugt bei Unterstützung den Post-Quantum-Hybrid X25519MLKEM768 und ist für alle bestehenden und neuen Zonen aktiviert.

Cloudflare now takes the guesswork out of TLS 1.3 key agreement with your origins. Automatic key exchange predicts the preferred algorithm and sends its key share in the first ClientHello, helping avoid a HelloRetryRequest and one extra network round trip.

Automatic key exchange is on for all existing zones and on by default for new zones. When an origin supports both classical and post-quantum key agreements, Cloudflare prefers the post-quantum X25519MLKEM768 hybrid key agreement.

To change this behavior, go to SSL/TLS > Overview > Origin connection & post-quantum encryption. Turn off Automatic key exchange to stop automatic scans and preference updates. Turning it off does not change your compliance requirements.

Compliance requirements apply only to TLS 1.3 connections. The Post-quantum hybrid option requires hybrid post-quantum key agreements support on your origin server. The Federal Information Processing Standards (FIPS) option requires FIPS-compliant key agreements. Select both to require key agreements that satisfy both, or leave both unselected to allow all supported key agreements.

For requirements, configuration options, and rollout details, refer to Automatic key exchange to origins.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-07-21

Neue Regeln decken Schwachstellen in Adobe ColdFusion, Next.js und WordPress ab, darunter CVE-2026-64641 in Next.js, und aktualisierte Regeln verbessern den generischen Schutz vor SSRF, LFI und XSS.

This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).

WAF and framework adapter mitigations for Next.js vulnerabilities

Multiple security vulnerabilities ↗︎ were disclosed and patched by the Next.js team through July 2026 security release. These include denial of service, middleware and proxy bypass, server-side request forgery, information disclosure, and cache poisoning across a range of severities.

Several of the disclosed vulnerabilities are not possible to block at WAF layer,we strongly recommend updating your application and its dependencies immediately. Patched versions are available through v16.2.11 (Active LTS) and v15.5.21 (Maintenance LTS) to address these issues.

Advisory

CVE

Severity

Issue

WAF Coverage

Denial of Service in App Router using Server Actions

CVE-2026-64641

High

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage. The CPU usage blocks processing of further requests in the same process, leading to Denial of Service.

WAF rule Next.js - DoS - CVE-2026-64641 (...90dcdb0a) has been deployed to provide coverage. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Account Roles API veraltet

Die Account Roles API ist veraltet und wird durch die Permission Groups API ersetzt, deren Antwortschema abweicht, wobei noch kein End-of-Life-Datum feststeht.

Cloudflare Fundamentals

The Account Roles API is deprecated and is being replaced by the Permission Groups API. An end of life date has not yet been established.

What you need to do

Review the Permission Groups API documentation; the response schema differs from the legacy Roles response.

Highlights

  • Integrations migrating to the Permission Groups API must obtain Permission Group IDs from that API and use them in the Account Members API policies request shape. Integrations that persist legacy Role IDs will need to remap their assignments.
  • The legacy Role response includes a top-level description and a permissions object keyed by resource type with edit/read flags.
  • The PermissionGroup response replaces those with a meta object containing label and scopes. Individual permissions are not returned as part of the permission group.
  • The new API supports the API Token authorization scheme. The legacy Email + API Key authorization schema is provided for backwards compatibility. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Account Roles API veraltet, Ersatz ist die Permission Groups API

Die Account Roles API ist deprecated und wird durch die Permission Groups API ersetzt, wobei sich das Antwortschema unterscheidet und Integrationen mit gespeicherten Role-IDs ihre Zuweisungen neu zuordnen müssen; ein End-of-Life-Datum steht noch nicht fest.

The Account Roles API is deprecated and is being replaced by the Permission Groups API. An end of life date has not yet been established.

What you need to do

Review the Permission Groups API documentation; the response schema differs from the legacy Roles response.

Highlights

  • Integrations migrating to the Permission Groups API must obtain Permission Group IDs from that API and use them in the Account Members API policies request shape. Integrations that persist legacy Role IDs will need to remap their assignments.
  • The legacy Role response includes a top-level description and a permissions object keyed by resource type with edit/read flags.
  • The PermissionGroup response replaces those with a meta object containing label and scopes. Individual permissions are not returned as part of the permission group.
  • The new API supports the API Token authorization scheme. The legacy Email + API Key authorization schema is provided for backwards compatibility. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browserbasierter Login für private HTTP-Anwendungen in Access

Private Anwendungen über unverschlüsseltes HTTP auf Port 80 nutzen in Cloudflare Access nun den standardmäßigen browserbasierten Login statt des Pop-up-Ablaufs des Cloudflare One Client, ohne dass eine Konfigurationsänderung nötig ist.

Cloudflare Access now uses the standard browser-based login flow for private applications served over plaintext HTTP on port 80.

Previously, plaintext HTTP private apps fell back to the same session flow used for SSH, RDP, and other non-HTTP protocols: users got an Authentication required pop-up from the Cloudflare One Client, then had to select the notification to open a browser and log in. Now, users hitting an HTTP private app see the Access login page directly in the browser and receive a standard Access application token on success.

This brings the HTTP experience in line with HTTPS apps (with Gateway TLS decryption turned on). No configuration change is required. The Cloudflare One Client is still required to route traffic to the private network, but it no longer manages the Access session for HTTP apps.

Other non-HTTP protocols (SSH, RDP, arbitrary TCP/UDP) continue to use the Cloudflare One Client notification flow.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Budget-Alerts jetzt standardmäßig für Pay-as-you-go-Konten aktiv

Für berechtigte Pay-as-you-go-Konten legt Cloudflare standardmäßig einen Budget-Alert mit 10-Dollar-Schwelle an, der ab dem nächsten Abrechnungszyklus aktiv wird und nur per E-Mail informiert.

We are turning on budget alerts by default for eligible Pay-as-you-go accounts. If your account does not already have a budget alert, Cloudflare will create one for you with a $10 account-level threshold. Your default alert will enable at the turn of your next billing cycle, so it will not fire based on usage you have already incurred.

We are rolling this out in cohorts over the coming weeks, so eligible accounts may see their default alert appear at different times.

The default alert behaves exactly like an alert you would create yourself. When your cumulative usage-based spend this cycle reaches the threshold, you receive an email notification. The alert is informational only. It does not cap your usage or impact your account in any way.

Usage is processed once per day for the prior day's activity, so budget alerts fire the day after the threshold is reached rather than in real time.

Budget alerts only consider spend on usage-based products. Recurring subscription fees, such as the Workers Paid plan fee or other monthly plan charges, are not included in the threshold calculation.

You can change the threshold, add additional alerts, or remove the default alert entirely from Manage Account > Billing > Billable Usage, or from your Notifications settings. If you already configured your own budget alert, nothing changes.

Enterprise contract accounts are not in scope. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Gesamten SQLite-Speicher von Durable-Object-Namespaces einsehen

Im Cloudflare-Dashboard zeigt ein neues Diagramm „Total storage“ den gesamten SQLite-Speicherverbrauch eines Durable-Object-Namespace über die Zeit.

You can now monitor the total SQLite storage used by a Durable Object namespace over time in the Cloudflare dashboard. The new Total storage chart shows the maximum storage reported during each hour. This helps you identify storage growth, validate data cleanup, and investigate unexpected usage.

The Total storage chart showing a Durable Object namespace growing to 260.1 MB of storage over time. Go to Durable Objects ↗

The chart appears only for SQLite-backed Durable Object namespaces. It does not appear for namespaces that use the legacy key-value storage backend. Viewing storage for individual Durable Objects by ID or name is not supported.

For more information, refer to Metrics and analytics.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Budget-Alerts jetzt standardmäßig für Pay-as-you-go-Accounts aktiv

Für berechtigte Pay-as-you-go-Accounts ohne Budget-Alert legt Cloudflare schrittweise einen Standard-Alert mit 10-$-Schwelle an, der zum nächsten Abrechnungszyklus aktiv wird, nur per E-Mail informiert und sich anpassen oder entfernen lässt.

We are turning on budget alerts by default for eligible Pay-as-you-go accounts. If your account does not already have a budget alert, Cloudflare will create one for you with a $10 account-level threshold. Your default alert will enable at the turn of your next billing cycle, so it will not fire based on usage you have already incurred.

We are rolling this out in cohorts over the coming weeks, so eligible accounts may see their default alert appear at different times.

The default alert behaves exactly like an alert you would create yourself. When your cumulative usage-based spend this cycle reaches the threshold, you receive an email notification. The alert is informational only. It does not cap your usage or impact your account in any way.

Usage is processed once per day for the prior day's activity, so budget alerts fire the day after the threshold is reached rather than in real time.

Budget alerts only consider spend on usage-based products. Recurring subscription fees, such as the Workers Paid plan fee or other monthly plan charges, are not included in the threshold calculation.

You can change the threshold, add additional alerts, or remove the default alert entirely from Manage Account > Billing > Billable Usage, or from your Notifications settings. If you already configured your own budget alert, nothing changes.

Enterprise contract accounts are not in scope. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Appliance per Dashboard neu starten oder herunterfahren

Eine Cloudflare One Appliance lässt sich nun per Dashboard oder API neu starten (Restart), rebooten oder herunterfahren.

You can now restart, reboot, or shut down a Cloudflare One Appliance directly from the dashboard or via API.

Restarting a Cloudflare One Appliance from the Operations section of the Edit Appliance page

  • Restart — Restart managed services. Purges temporary and (optionally) persistent state.
  • Reboot — Power cycle the appliance. Optionally, purge persistent state. Re-applies configuration starting from scratch.
  • Shutdown — Power off the appliance. Optionally, purge persistent state. The machine will be offline until manually powered on again.

In the dashboard, go to Networking > Connectors > Appliances, select an appliance, then Edit > Operations to send an operation. Via API, POST to the /accounts/{account_id}/magic/connectors/{connector_id}/interrupts endpoint.

For details, refer to Appliance operations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Header-Optionen für Gateway-HTTP-Richtlinien

Gateway-HTTP-Allow-Richtlinien können nun Header von passenden Anfragen hinzufügen, überschreiben oder löschen und dabei statische Werte oder dynamische Variablen mit @{...}-Syntax verwenden.

Cloudflare Gateway now supports advanced header control on Allow policies. Administrators can add, overwrite, or delete headers on matching requests using static values or dynamic variables.

Header operations

Gateway HTTP policies using the Allow action support three operations in rule_settings:

Operation

API field

Behavior

Add

add_headers

Appends a value to the header. Existing values are preserved.

Overwrite

set_headers

Replaces the header value. Creates the header if it does not exist.

Delete

delete_headers

Removes the header from the request.

Gateway applies operations in order: delete, then overwrite, then add.

Dynamic variables

Header values can include dynamic variables using the @{...} syntax. Gateway resolves variables at request time from identity, device, and network context.

Variable

Description

@{identity.email}

User email from the identity provider

@{identity.name}

User display name from the identity provider

@{identity.id}

Cloudflare identity UUID

@{identity.groups}

Identity provider group memberships

@{identity.SAML}

SAML attributes (if configured)

@{identity.OIDC}

OIDC claims (if configured)

@{source.ip}

Source IP of the connection

@{destination.ip}

Destination IP of the request

@{device.id}

Cloudflare One Client device UUID

@{device.posture} …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Vorschau gesendeter E-Mails im Activity log des Email Service

Im Activity log des Email Service lassen sich gesendete E-Mails jetzt in einer Vorschau mit HTML, Text, Headern, Anhängen und Rohquelltext ansehen, sofern „Email preview“ aktiviert ist.

You can now preview the content of sent emails directly from the Email Service Activity log. Expand a sent email and open the new Preview section to inspect the message as it was sent, across tabs for the rendered HTML body, the Text body, the Headers, the Attachments, and the full Raw RFC 5322 ↗︎ source.

The rendered HTML preview of a sent email in the Email Service Activity log

Previously, the Activity log surfaced delivery and authentication metadata but not the message content, making rendering and content issues harder to debug. Message preview closes that gap.

To make messages previewable, turn on Email preview in your sending domain's settings. Previews cover messages sent while the setting is turned on and are retained for about seven days. Sending domains onboarded on or after 2026-07-02 have Email preview turned on automatically.

The Email preview setting in a sending domain's settings

Refer to Email logs for more information.

Originalquelle(öffnet in neuem Tab)Problem melden