Zum Inhalt springen

Cloudflare Release Notes

1.617 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Google-Artifact-Registry-Images mit Containers nutzen

Containers unterstützen nun Images aus der Google Artifact Registry, die nach dem Einrichten der Zugangsdaten direkt in der Wrangler-Konfiguration referenziert werden können, ohne sie zuvor in die Cloudflare Registry zu pushen.

Containers now support Google Artifact Registry ↗︎ images. After you configure credentials, you can use a fully qualified Google Artifact Registry image reference in your Wrangler configuration instead of first pushing the image to Cloudflare Registry.

Provide the service account email with --gar-email and pipe the service account JSON key through stdin:

cat <PATH_TO_KEY> | npx wrangler containers registries configure <REGION>-docker.pkg.dev --gar-email=<SERVICE_ACCOUNT_EMAIL> --secret-name=<SECRET_NAME>
{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "containers": [
    {
      "image": "<REGION>-docker.pkg.dev/<PROJECT_ID>/<REPOSITORY>/<IMAGE>:<TAG>"
    }
  ]
}
# Example: us-central1-docker.pkg.dev/my-project/my-repo/my-image:latest
[[containers]]
image = "<REGION>-docker.pkg.dev/<PROJECT_ID>/<REPOSITORY>/<IMAGE>:<TAG>"

Only *-docker.pkg.dev hosts are supported. To configure credentials, refer to Use private Google Artifact Registry images.

For more information, refer to Image management.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Images-Binding wird pro einzigartiger Transformation abgerechnet

Das Images-Binding wird nun pro einzigartiger Transformation abgerechnet, wobei wiederholte Anfragen mit gleichem Quellbild und gleichen Parametern im selben Kalendermonat nur einmal zählen und Aufrufe von .info() nicht mehr berechnet werden.

The Images binding is now billed per unique transformation, matching the model already used for URL-based transformations. Repeat requests for the same combination of source image and parameters within the same calendar month are counted only once.

Previously, every call to the binding counted as a separate transformation regardless of whether the image or parameters were unique. With this change, you can call the binding on hot paths without paying for each individual request.

Calls to .info() are no longer billed.

For more information, refer to Images pricing and the Images binding documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Vectorize: geringere Latenz bei Vektoränderungen

Durch einen verbesserten Durchsatz des Write-Ahead-Logs in Vectorize sind Vektoränderungen schneller abfragbar, wobei die mediane Latenz von 2 Minuten auf unter 30 Sekunden und die p99-Latenz von 5 Minuten auf unter 2 Minuten sank, ohne dass Code oder Konfiguration geändert werden müssen.

We have greatly improved the throughput of the Vectorize write-ahead log (WAL) ↗︎. As a result, we have significantly reduced the end-to-end latency for a vector change to become queryable: median latency has dropped from 2 minutes to under 30 seconds, and p99 latency from 5 minutes to under 2 minutes.

Vectorize p99 WAL batch end-to-end latency improved

This means inserts, upserts, and deletes are reflected in query results faster, improving the freshness of semantic search, recommendation, and retrieval-augmented generation (RAG) workloads. You do not need to change your code or configuration to benefit from this improvement.

For more information, refer to the Vectorize documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Neue Optionen für KI-Traffic in Bots

Alle Kunden können KI-Crawler jetzt anhand ihres Verhaltens (Search, Agent, Training) steuern und wahlweise auf allen Seiten, nur auf Werbeseiten oder gar nicht blocken.

Not all AI traffic is the same. Now, all customers — including those on the Free plan — can manage AI crawlers based on what they actually do on your site. Cloudflare groups AI traffic into three behaviors you can control independently: Search, Agent, and Training. This lets you keep the automated traffic that sends readers and revenue back to you, while blocking the traffic that only takes from your content.

Each behavior maps to a real use case. Search covers crawlers that index your content so they can answer questions about it later, where you should expect referral traffic or other equitable compensation in return. Agent covers automated activity acting in real time on a person's behalf, such as chat fetch bots and browser-use agents. Training covers crawlers that take your content to train or fine-tune a model. For each preset you can choose to block on all pages, block only on pages that display ads, or choose not to block.

The Configure AI bot traffic policies screen, where Search, Agent, and Training can each be set to allow, block, or block only on pages with ads …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

BotBase und Business Insights für Enterprise Bot Management

Enterprise Bot Management-Kunden erhalten mit BotBase ein durchsuchbares Bot-Verzeichnis und mit Business Insights ein Dashboard zum Wert von Crawler-Traffic.

With Content Independence Day 2026, Enterprise Bot Management customers get two new tools that make bot traffic far easier to see and reason about: BotBase, a searchable directory of every bot Cloudflare tracks, and Business Insights, a dashboard that shows how much value each crawler sends back to your business.

BotBase is Cloudflare's directory of all known bots and agents, available directly in the dashboard. It shows how Cloudflare classifies each bot by behavior — Search, Agent, Training, and other categories such as Transact, Data Collection, SEO, and Ads Verification — so you can understand why a given crawler is visiting you. You can search and filter the full catalogue, filter your own traffic down to a single bot to investigate its activity on your zone, and copy any bot's detection ID to target it precisely in Security rules. Every tracked bot in BotBase is also published in Cloudflare Radar's bots and agents directory ↗︎. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF-Update: FortiSandbox-Regel und Fake-Bing-Bot

Das WAF-Update fügt eine neue Block-Regel für eine Path-Traversal-Schwachstelle in Fortinet FortiSandbox hinzu und deaktiviert die Regel für gefälschte Bing- oder MSN-Bots.

This release adds targeted coverage for a path traversal flaw in Fortinet FortiSandbox (CVE-2026-39813) and transitions the Anomaly:Header:User-Agent - Fake Bing or MSN Bot rule action from Block to Disabled.

Key Findings

  • CVE-2026-39813: A path traversal vulnerability in Fortinet FortiSandbox allows remote, unauthenticated attackers to read arbitrary files from the underlying filesystem due to insufficient validation of user-supplied input paths.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...d84c92c9

N/A

Fortinet FortiSandbox - Path Traversal - CVE:CVE-2026-39813

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...c12cf9c8

N/A

Anomaly:Header:User-Agent - Fake Bing or MSN Bot

Enabled

Disabled

We are changing the action for this rule from BLOCK to Disabled

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Media von Cloudflare

Images binding wird pro eindeutiger Transformation abgerechnet

Das Images binding wird nun pro eindeutiger Transformation abgerechnet, wiederholte Anfragen mit gleicher Bild- und Parameterkombination werden im Monat nur einmal gezählt, und .info()-Aufrufe sind kostenlos.

Cloudflare Images

The Images binding is now billed per unique transformation, matching the model already used for URL-based transformations. Repeat requests for the same combination of source image and parameters within the same calendar month are counted only once.

Previously, every call to the binding counted as a separate transformation regardless of whether the image or parameters were unique. With this change, you can call the binding on hot paths without paying for each individual request.

Calls to .info() are no longer billed.

For more information, refer to Images pricing and the Images binding documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Rollen für Gateway-Policies und Zero-Trust-Listen

Für Gateway-Firewall-Policies und Zero-Trust-Listen gibt es neue ressourcenbezogene Rollen, mit denen Administratoren gezielt Zugriff auf bestimmte Policy-Typen oder Listenverwaltung delegieren können, ohne kontoweite Rechte zu vergeben.

You can now assign granular, resource-scoped roles for Cloudflare Gateway firewall policies and Zero Trust lists. Administrators can delegate access to specific policy types or list management without granting account-wide or product-wide control.

What is new

When you add a member or create a permission policy, the following resource-scoped roles are now available:

Role

Description

Zero Trust Gateway Firewall Policies Admin

Can view and edit all Gateway firewall policies, including DNS, HTTP, and Network policies.

Zero Trust Gateway DNS Policies Admin

Can view and edit Gateway DNS policies.

Zero Trust Gateway HTTP Policies Admin

Can view and edit Gateway HTTP policies.

Zero Trust Gateway Network Policies Admin

Can view and edit Gateway Network policies.

Zero Trust Gateway Egress Policies Admin

Can view and edit Gateway Egress policies.

Zero Trust Gateway Resolver Policies Admin

Can view and edit Gateway Resolver policies.

Zero Trust Gateway Policies Admin

Can view and edit all Gateway policies.

Zero Trust Gateway Policies Read

Can view all Gateway policies.

Zero Trust Gateway Read Only

Can view all Gateway resources. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Speichernutzung von Workers und Durable Objects im Dashboard

Im Metrics-Tab von Workers zeigt ein neues Diagramm „Memory Usage“ die Speichernutzung von Workers und Durable Objects nach den Perzentilen P50, P90, P99 und P999 sowie mit Deployment-Markierungen.

You can now monitor how much memory your Workers and Durable Objects consume across invocations with the new Memory Usage chart in the Workers Metrics tab, broken down by P50, P90, P99, and P999 percentiles.

Memory usage chart showing P50, P90, P99, and P999 percentiles with deployment markers

Memory usage measures the V8 isolate memory at the time of each invocation, subject to the 128 MB per-isolate limit — a single isolate can handle many concurrent requests and shares memory across them.

Use the Memory Usage chart to:

  • Track memory trends — Spot gradual increases that may indicate a memory leak before they cause Exceeded Memory errors.
  • Correlate with deployments — Deployment markers on the chart help you identify whether a new version introduced a memory regression.
  • Right-size your Worker — Understand your baseline memory footprint and how much headroom you have before hitting the 128 MB limit. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Firewall-Ereignisse als Account-weiter Logpush-Datensatz

Logpush unterstützt jetzt Firewall-Ereignisse als Account-weiten Datensatz, sodass ein einziger Job Ereignisse für alle Zonen liefert, inklusive neuem ZoneName-Feld.

Logs

Cloudflare Logpush now supports firewall events as an account-scoped dataset. Configure a single Logpush job at the account level to receive firewall events for every zone in the account, instead of creating and maintaining a separate job per zone.

The dataset includes a new ZoneName field so you can identify which zone each event came from when consuming logs in your downstream pipeline.

What's available

  • A new account-scoped firewall_events dataset, configurable via the Logpush API or the Cloudflare dashboard.
  • The same fields and filter expressions supported by the existing zone-scoped firewall events dataset, plus the new ZoneName field.
  • Support for all existing Logpush destinations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Neue Rollen für Gateway-Richtlinien und Listen

Administratoren können nun granulare, ressourcenbezogene Rollen für Gateway-Firewall-Richtlinien und Zero-Trust-Listen zuweisen, ohne kontoweite Berechtigungen zu erteilen.

Gateway Cloudflare One Cloudflare Fundamentals

You can now assign granular, resource-scoped roles for Cloudflare Gateway firewall policies and Zero Trust lists. Administrators can delegate access to specific policy types or list management without granting account-wide or product-wide control.

What is new

When you add a member or create a permission policy, the following resource-scoped roles are now available:

Role Description
Zero Trust Gateway Firewall Policies Admin Can view and edit all Gateway firewall policies, including DNS, HTTP, and Network policies.
Zero Trust Gateway DNS Policies Admin Can view and edit Gateway DNS policies.
Zero Trust Gateway HTTP Policies Admin Can view and edit Gateway HTTP policies.
Zero Trust Gateway Network Policies Admin Can view and edit Gateway Network policies.
Zero Trust Gateway Egress Policies Admin Can view and edit Gateway Egress policies.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Neue Rollen für Gateway-Richtlinien und Listen

Administratoren können jetzt granulare, ressourcengebundene Rollen für Gateway-Firewall-Richtlinien und Zero-Trust-Listen zuweisen.

You can now assign granular, resource-scoped roles for Cloudflare Gateway firewall policies and Zero Trust lists. Administrators can delegate access to specific policy types or list management without granting account-wide or product-wide control.

What is new

When you add a member or create a permission policy, the following resource-scoped roles are now available:

Role

Description

Zero Trust Gateway Firewall Policies Admin

Can view and edit all Gateway firewall policies, including DNS, HTTP, and Network policies.

Zero Trust Gateway DNS Policies Admin

Can view and edit Gateway DNS policies.

Zero Trust Gateway HTTP Policies Admin

Can view and edit Gateway HTTP policies.

Zero Trust Gateway Network Policies Admin

Can view and edit Gateway Network policies.

Zero Trust Gateway Egress Policies Admin

Can view and edit Gateway Egress policies.

Zero Trust Gateway Resolver Policies Admin

Can view and edit Gateway Resolver policies.

Zero Trust Gateway Policies Admin

Can view and edit all Gateway policies.

Zero Trust Gateway Policies Read

Can view all Gateway policies.

Zero Trust Gateway Read Only

Can view all Gateway resources. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Firewall-Ereignisse als kontobezogener Logpush-Datensatz

Logpush unterstützt jetzt Firewall-Ereignisse als kontobezogenen Datensatz, sodass ein einzelner Job Ereignisse für alle Zonen des Kontos erfasst.

Cloudflare Logpush now supports firewall events as an account-scoped dataset. Configure a single Logpush job at the account level to receive firewall events for every zone in the account, instead of creating and maintaining a separate job per zone.

The dataset includes a new ZoneName field so you can identify which zone each event came from when consuming logs in your downstream pipeline.

What's available

  • A new account-scoped firewall_events dataset, configurable via the Logpush API or the Cloudflare dashboard.
  • The same fields and filter expressions supported by the existing zone-scoped firewall events dataset, plus the new ZoneName field.
  • Support for all existing Logpush destinations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.6.822.0 (GA)

Das GA-Release des Cloudflare One Client für Windows übernimmt Funktionen aus der Beta, darunter per Device Profile bzw. Network Policy verteilte DNS-Suchsuffixe und eine per MDM aktivierbare Pflichtauthentifizierung, die bis zur Anmeldung des Nutzers den gesamten Internetverkehr blockiert.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Added mandatory authentication. When enabled via MDM, the Cloudflare One Client blocks all Internet traffic from the moment the machine boots until the user authenticates, closing the visibility gap on newly deployed devices. See the announcement blog and documentation for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.6.822.0

Das GA-Release bringt Beta-Funktionen in die stabile Version, darunter DNS-Suchsuffixe aus Device Profile bzw. Network Policy und hardwaregestützte Geräteregistrierung über die Secure Enclave.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation. See Hardware-backed registration for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.6.822.0

Das GA-Release bringt Beta-Funktionen in die stabile Version, darunter DNS-Suchsuffixe aus Device Profile bzw. Network Policy und hardwaregestützte Geräteregistrierung über das TPM (ab TPM 2.0).

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release introduces multiple features from our previous beta release into stable release, including:

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details.
  • Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the TPM (with TPM 2.0+) whenever it is available to provide stronger protection against device impersonation. See Hardware-backed registration for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers fetch unterstützt jetzt cf.vary

Workers-fetch()-Anfragen unterstützen nun die Option cf.vary, mit der sich pro Subrequest steuern lässt, wie Cloudflare Origin-Antworten mit Vary-Header cacht.

Workers fetch() requests now support the cf.vary request option. Use cf.vary to control how Cloudflare caches origin responses with a Vary header for a single subrequest.

src/index.jsjs

export default {
	async fetch(request) {
		return fetch(request, {
			cf: {
				vary: {
					default: { action: "bypass" },
					headers: {
						accept: {
							action: "normalize",
							media_types: ["text/html", "application/json"],
						},
						"accept-language": {
							action: "normalize",
							languages: ["en", "fr", "de"],
						},
					},
				},
			},
		});
	},
};

src/index.tsts

export default {
	async fetch(request): Promise<Response> {
		return fetch(request, {
			cf: {
				vary: {
					default: { action: "bypass" },
					headers: {
						accept: {
							action: "normalize",
							media_types: ["text/html", "application/json"],
						},
						"accept-language": {
							action: "normalize",
							languages: ["en", "fr", "de"],
						},
					},
				},
			},
		});
	},
} satisfies ExportedHandler;

For more information, refer to cf.vary.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Service-Token-Unterstützung für MCP-Server-Portale

Autonome Agenten und Bots können sich nun mit einem Access Service Token ohne browserbasierten OAuth-Ablauf mit einem MCP-Server-Portal verbinden, sofern Service-Auth-Policies eingerichtet und „Require user auth“ für die verknüpften Server deaktiviert ist.

You can now connect autonomous agents and bots to an MCP server portal using an Access service token. Service token sessions can reach upstream MCP servers through the portal without a browser-based OAuth flow.

To set this up:

  • Add a Service Auth policy that matches your service token to the portal's Access application.
  • Add a Service Auth policy that matches the same token to each linked MCP server's Access application.
  • Turn Require user auth off (on_behalf: false) for each linked server so the portal uses the admin credential instead of a per-user OAuth grant.

The bot connects with CF-Access-Client-Id and CF-Access-Client-Secret headers and sees the tools from every linked server it is authorized for. Servers that still require per-user OAuth are excluded from service token sessions because a service token cannot complete a per-user OAuth grant.

For step-by-step setup, refer to Connect with a service token.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Agents SDK: Hintergrund-Sub-Agents und einheitlicher Turn-Einstieg

Das Agents SDK erlaubt nun losgelöste Sub-Agent-Läufe im Hintergrund mit Fortschrittsanzeige und dauerhaften Meilensteinen, bietet mit runTurn einen einzigen Einstiegspunkt für Turns und enthält zahlreiche Verbesserungen bei Wiederherstellung und Zuverlässigkeit.

The latest release of the Agents SDK ↗︎ makes it easier to run long work in the background, drive turns through one entry point, and keep chat agents working through deploys, evictions, and reconnects.

This release adds first-class detached (background) sub-agent runs with live progress and durable milestones, a single runTurn turn-admission entry point, and a large round of recovery and reliability fixes that continue converging @cloudflare/think and @cloudflare/ai-chat onto one model.

Background sub-agents with progress and milestones

runAgentTool can now dispatch a sub-agent without blocking the calling turn. A detached run returns a handle immediately and is owned by a durable, eviction-surviving backbone instead of being abandoned when the dispatching turn ends.

class OrdersAgent extends Think {
	async startImport(input) {
		// Fire-and-forget, or wire a durable completion callback
		// (by method name, like schedule()):
		await this.runAgentTool(ImportAgent, {
			input,
			detached: { onFinish: "onImportDone", maxBudgetMs: 60 * 60 * 1000 },
		});
	}

	// result.status: "completed" | "error" | "aborted" | "interrupted"
	async onImportDone(run, result) {}
}
class OrdersAgent extends Think {
	async startImport(input) {
		// Fire-and-forget, or wire a durable completion callback
		// (by method name, like schedule()): …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Neue us-Jurisdiktion für Durable Objects

Durable Objects unterstützen nun die Jurisdiktion us, mit der sich Durable Objects erstellen lassen, die ausschließlich in den USA laufen und Daten speichern, während Workers weiterhin von überall darauf zugreifen können.

Durable Objects now supports a us jurisdiction, letting you create Durable Objects that only run and store data within the United States. Use the us jurisdiction when you need to keep a Durable Object's compute and storage inside the United States to meet data residency requirements.

Create a namespace restricted to the us jurisdiction the same way as any other jurisdiction:

// Worker
export default {
	async fetch(request, env) {
		const usSubnamespace = env.MY_DURABLE_OBJECT.jurisdiction("us");
		const stub = usSubnamespace.getByName("general");
		return stub.fetch(request);
	},
};

Workers may still access Durable Objects constrained to the us jurisdiction from anywhere in the world. The jurisdiction constraint only controls where the Durable Object itself runs and persists data.

For the full list of supported jurisdictions, refer to Data location — Restrict Durable Objects to a jurisdiction.

Originalquelle(öffnet in neuem Tab)Problem melden