Zum Inhalt springen

Cloudflare Release Notes

1.617 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Neue us-Jurisdiktion für Durable Objects

Durable Objects unterstützen jetzt eine us-Jurisdiktion, mit der sich Ausführung und Datenspeicherung eines Objekts auf die USA beschränken lassen, während Workers weiterhin weltweit darauf zugreifen können.

Durable Objects now supports a us jurisdiction, letting you create Durable Objects that only run and store data within the United States. Use the us jurisdiction when you need to keep a Durable Object's compute and storage inside the United States to meet data residency requirements.

Create a namespace restricted to the us jurisdiction the same way as any other jurisdiction:

// Worker
export default {
	async fetch(request, env) {
		const usSubnamespace = env.MY_DURABLE_OBJECT.jurisdiction("us");
		const stub = usSubnamespace.getByName("general");
		return stub.fetch(request);
	},
};

Workers may still access Durable Objects constrained to the us jurisdiction from anywhere in the world. The jurisdiction constraint only controls where the Durable Object itself runs and persists data.

For the full list of supported jurisdictions, refer to Data location — Restrict Durable Objects to a jurisdiction.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Durable-Object-Eviction mit neuen cloudflare:test-Helfern testen

Das Paket @cloudflare/vitest-pool-workers enthält ab Version 0.16.20 die Test-Helfer evictDurableObject und evictAllDurableObjects, mit denen sich das Verhalten von Durable Objects bei Eviction simulieren lässt.

The @cloudflare/vitest-pool-workers package now includes evictDurableObject and evictAllDurableObjects test helpers, exported from cloudflare:test.

These helpers let you test how a Durable Object behaves across evictions, simulating the production lifecycle where an idle Durable Object can be evicted from memory.

For more context, refer to Lifecycle of a Durable Object.

import { evictDurableObject, evictAllDurableObjects } from "cloudflare:test";
import { env } from "cloudflare:workers";

const id = env.COUNTER.idFromName("my-counter");
const stub = env.COUNTER.get(id);

// Evict the Durable Object instance pointed to by a specific stub
await evictDurableObject(stub);

// Close WebSockets instead of hibernating them
await evictDurableObject(stub, { webSockets: "close" });

// Evict all currently-running Durable Objects in evictable namespaces
await evictAllDurableObjects();

These helpers are available in @cloudflare/vitest-pool-workers@0.16.20 and later.

Learn more in the Test APIs reference and the Testing Durable Objects guide.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

API-Tokens nach Namen suchen

API-Tokens können nun im Dashboard und über die API nach Namen gesucht werden, was das Auffinden spezifischer Tokens erleichtert.

Cloudflare Fundamentals

You can now search API tokens by name, making it easier to find specific tokens across large token lists without manually paginating.

What's new

For more information, refer to Create an API token and Account API tokens.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

API-Tokens nach Namen durchsuchbar

API-Tokens können jetzt im Dashboard und über die API nach Namen durchsucht werden, um große Token-Listen einfacher zu filtern.

You can now search API tokens by name, making it easier to find specific tokens across large token lists without manually paginating.

What's new

For more information, refer to Create an API token and Account API tokens.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS Beta 2026.6.782.1

Das Beta-Release führt hardwaregestützte Geräteregistrierung über die Secure Enclave ein und bringt Verbesserungen wie besseren Hochkontrast-Support, standardmäßig aktiviertes PMTUD sowie Fixes bei DNS-Abfragen nach Leerlauf und mehrere UI-Korrekturen.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This beta release introduces upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation.

Additional changes and improvements

This release also introduces multiple fixes and improvements including:

  • Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in the macOS Display settings.
  • Path MTU Discovery (PMTUD) is now enabled by default.
  • Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.
  • Users can now register with team names in any case format without errors.
  • New UI fixes
    • Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.
    • Added a re-auth button and banner to the home screen so users don't miss it when their session expires.
    • Added clear error messaging when the Cloudflare certificate needs to be installed.
    • Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Search: Aktualität des Similarity Cache steuern

In AI Search richtet sich die Cache-Dauer nun nach der Instanz-Einstellung cache_ttl mit einem Standard von 48 Stunden statt bisher 30 Tagen und einstellbar von 10 Minuten bis 6 Tage, außerdem lassen sich alle gecachten Antworten einer Instanz bei Bedarf löschen.

AI Search now gives you more control over similarity cache freshness. Similarity cache helps reduce latency and inference cost by reusing responses for semantically similar queries.

With these updates, you can choose how long responses are eligible for reuse and clear cached responses when they may be stale.

Cache duration now defaults to 48 hours

Previously, AI Search cached responses for a fixed duration of 30 days. Cached responses now use the instance's cache_ttl setting, and the default is 48 hours.

You can set cache_ttl when creating or updating an instance to choose a cache duration from 10 minutes to 6 days.

Use a shorter TTL when your source content changes frequently and freshness is more important. Use a longer TTL when your content is stable and you want more cache reuse.

For example, set cache_ttl to 518400 to retain cached responses for 6 days:

{
	"cache_ttl": 518400
}

Purge cached responses

You can also purge all cached responses for an instance on demand. Purging cached responses does not delete indexed content or source files.

It prevents AI Search from reusing previous cached responses, so subsequent similar queries generate fresh answers and repopulate the cache.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Neuer WebSocket-Analytics-Logpush-Datensatz und aktualisierte Felder

Cloudflare hat einen neuen WebSocket-Analytics-Logpush-Datensatz eingeführt und die Felder in Firewall- und E-Mail-Sicherheitsdatensätzen erweitert.

Logs

Cloudflare has updated Logpush datasets:

New datasets

  • WebSocket Analytics: A new dataset with fields including BytesReceivedClient, BytesReceivedOrigin, BytesSentClient, BytesSentOrigin, ClientASN, ClientIP, ClientRequestHost, ClientRequestPath, ClientRequestUserAgent, ColoCode, ConnectionCloseReason, ConnectionCloseSource, ConnectionID, ConnectionTransportCloseCode, EdgeEndTimestamp, EdgeStartTimestamp, and RayID.

Updated fields in existing datasets

  • Firewall events (added): ZoneName. The Firewall events dataset is now also available for account-scope Logpush, in addition to the existing zone scope.
  • Email Security Alerts (added): BCC, DKIMResult, DMARCPolicy, DMARCResult, and SPFResult.

For the complete field definitions for each dataset, refer to Logpush datasets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Präzisere IP-Standort- und AS-Details auf der Cloudflare-Radar-IP-Seite

Die Radar-IP-Seite zeigt jetzt detaillierte Standortmarkierungen für IPv4 und IPv6, Cloudflare-Rechenzentren und erweiterte Informationen zum autonomen System.

Radar

Radar now plots your IPv4 and IPv6 locations on the IP page ↗︎, shows the Cloudflare data centers serving your connection, and includes more detail about the autonomous system (AS) your primary IP belongs to.

Your IP location on the map

The map of your connection now shows:

  • IP location markers — The primary IP will show as a red marker. When both IP addresses do not geolocate to the same place, a second marker will appear in blue with a note explaining why IPv4 and IPv6 can resolve to different locations.
  • Cloudflare data center markers — Cloudflare data centers now show as orange dots on the map and the one you are connected to is highlighted.
  • Data center connectors — Each line connects your IP markers to their respective data centers.

Map showing Cloudflare data centers and a marker representing the IP location with a line connected to a data center

Due to the data policies of our geolocation provider, this detailed location is only available for your own IP. Other IP addresses keep the current country-level view.

Extended AS information …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Radar IP-Seite: Standortdetails und AS-Infos

Die Cloudflare-Radar-IP-Seite zeigt nun die genaue Position von IPv4- und IPv6-Adressen auf einer Karte, markiert die verbundenen Cloudflare-Rechenzentren und bietet erweiterte Details zum autonomen System.

Radar

Radar now plots your IPv4 and IPv6 locations on the IP page ↗︎, shows the Cloudflare data centers serving your connection, and includes more detail about the autonomous system (AS) your primary IP belongs to.

Your IP location on the map

The map of your connection now shows:

  • IP location markers — The primary IP will show as a red marker. When both IP addresses do not geolocate to the same place, a second marker will appear in blue with a note explaining why IPv4 and IPv6 can resolve to different locations.
  • Cloudflare data center markers — Cloudflare data centers now show as orange dots on the map and the one you are connected to is highlighted.
  • Data center connectors — Each line connects your IP markers to their respective data centers.

Map showing Cloudflare data centers and a marker representing the IP location with a line connected to a data center

Due to the data policies of our geolocation provider, this detailed location is only available for your own IP. Other IP addresses keep the current country-level view.

Extended AS information …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Audit-Logs auf Organisationsebene im Dashboard

Organisations-Superadministratoren können jetzt organisationsweite Audit-Logs im Cloudflare-Dashboard einsehen und filtern.

You can now, as an Organization Super Administrator, view organization-level audit logs in the Cloudflare dashboard, in addition to the existing API access.

Organization audit logs help you monitor activity across your organization. You can see who performed an action, what changed, when it happened, how it was performed, and whether it succeeded or failed.

You can filter and search logs by actor, action, result, resource, request details, and timestamp. Use these logs to troubleshoot changes, investigate unexpected access, and support security or compliance workflows.

Organization audit logs in the Cloudflare dashboard

If you are viewing account-level audit logs and the account belongs to an organization where you are an Organization Super Administrator, select View Organization Audit Logs to open the parent organization's audit logs.

View Organization Audit Logs button …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Logpush: Neuer WebSocket-Analytics-Datensatz und Feldaktualisierungen

Logpush erhält einen neuen WebSocket-Analytics-Datensatz sowie neue Felder in den Datensätzen für Firewall-Ereignisse und E-Mail-Sicherheitswarnungen.

Cloudflare has updated Logpush datasets:

New datasets

  • WebSocket Analytics: A new dataset with fields including BytesReceivedClient, BytesReceivedOrigin, BytesSentClient, BytesSentOrigin, ClientASN, ClientIP, ClientRequestHost, ClientRequestPath, ClientRequestUserAgent, ColoCode, ConnectionCloseReason, ConnectionCloseSource, ConnectionID, ConnectionTransportCloseCode, EdgeEndTimestamp, EdgeStartTimestamp, and RayID.

Updated fields in existing datasets

  • Firewall events (added): ZoneName. The Firewall events dataset is now also available for account-scope Logpush, in addition to the existing zone scope.
  • Email Security Alerts (added): BCC, DKIMResult, DMARCPolicy, DMARCResult, and SPFResult.

For the complete field definitions for each dataset, refer to Logpush datasets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Regionalized IP Bindings für Regional Services

Regional Services unterstützt nun Regionalized IP Bindings, mit denen sich CIDRs aus eigenen BYOIP-Präfixen an eine Region binden lassen, sodass TLS-Terminierung und Verarbeitung nur in Rechenzentren dieser Region erfolgen.

Regional Services now supports Regionalized IP Bindings, letting you regionalize traffic at the IP layer for prefixes you bring to Cloudflare through Bring Your Own IP (BYOIP).

Where Regional Hostnames regionalize traffic by hostname, Regionalized IP Bindings let you bind a CIDR from one of your prefixes to a region — ideal for address-map deployments and any service you address by IP rather than hostname. Cloudflare then terminates TLS and processes traffic to those addresses only within the data centers in that region.

Regionalized IP Bindings requires the Regional Services and Regional Services for BYOIP entitlements. Contact your account team to enable them.

To get started, refer to Regionalized IP Bindings.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workflows-Rollback-Handler erhalten Step-Kontext

Rollback-Handler in Workflows erhalten nun über ein ctx-Objekt den ursprünglichen Step-Kontext des zurückgerollten Steps, einschließlich Step-Name, Zähler, Versuchsnummer und der Step-Konfiguration mit angewendeten Standardwerten.

Workflows makes it easier to build reliable multi-step applications that can recover when downstream systems fail. Rollback handlers now receive the original step context via a ctx object for the step being rolled back. This includes ctx.step.name, ctx.step.count, ctx.attempt, and the step config with defaults applied.

The step configuration includes the retry and timeout settings used for that step, so you can customize your step recovery logic according to those fields.

await step.do(
	"create charge",
	async () => {
		const charge = await createCharge();
		return { chargeId: charge.id };
	},
	{
		rollback: async ({ ctx, output, error }) => {
			// `output` is the value returned by the step being rolled back.
			const { chargeId } = output as { chargeId: string };
			await refundCharge(chargeId, {
				// `ctx` is the original step context, including step name, count, attempt, and config.
				reason: `${ctx.step.name}: ${error.message}`,
			});
		},
		rollbackConfig: {
			// `rollbackConfig` controls retries and timeout for the rollback handler.
			retries: { limit: 3, delay: "30 seconds", backoff: "linear" },
			timeout: "5 minutes",
		},
	},
);
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

AMP/SXG eingestellt

Cloudflare hat die Unterstützung für AMP und SXG eingestellt; die Funktionen sind seit Oktober 2025 deaktiviert und können nicht mehr konfiguriert werden.

Cloudflare Accelerated Mobile Pages (AMP) and Signed Exchanges (SXG) support has reached end of life. The features have been disabled since October 2025, so customers who had them configured should see no change to their traffic.

Customers will no longer be able to configure AMP/SXG through API or rulesets. The Zone API will start throwing errors. Rulesets with the SXG configuration will fail to save until SXG has been removed.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF-Update: Ivanti-Sentry-Regel

Das WAF-Update fügt eine neue Block-Regel für eine kritische OS-Command-Injection-Schwachstelle in Ivanti Sentry hinzu.

This week's release introduces new managed protection to address a critical pre-authentication OS command injection vulnerability in Ivanti Sentry (CVE-2026-10520).

Key Findings

  • CVE-2026-10520: An OS command injection vulnerability in Ivanti Sentry allows remote, unauthenticated attackers to execute arbitrary system commands with root privileges. The flaw stems from improper sanitization of input strings parsed during internal configuration handling.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...242fdf83

N/A

Ivanti Sentry - Command Injection - CVE:CVE-2026-10520

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

R2 SQL unterstützt Window Functions, DISTINCT und Set Operations

R2 SQL unterstützt nun Window Functions, QUALIFY, SELECT DISTINCT, Set Operations wie UNION, INTERSECT und EXCEPT, Grouping-Erweiterungen wie ROLLUP und CUBE sowie zusätzliche exakte Aggregatfunktionen.

R2 SQL now supports window functions, SELECT DISTINCT, set operations, and additional aggregates, making it easier to write analytical queries without preprocessing your data elsewhere.

R2 SQL is Cloudflare's serverless, distributed SQL engine for querying Apache Iceberg ↗︎ tables stored in R2 Data Catalog.

New capabilities

  • Window functions — ROW_NUMBER, RANK, DENSE_RANK, PERCENT_RANK, CUME_DIST, NTILE, LAG, LEAD, FIRST_VALUE, LAST_VALUE, NTH_VALUE, and aggregates with an OVER (...) clause, including PARTITION BY and explicit frames
  • QUALIFY — filter rows based on a window function result
  • DISTINCT — SELECT DISTINCT, DISTINCT ON (...), and the DISTINCT modifier on aggregates such as COUNT(DISTINCT ...)
  • Set operations — UNION, UNION ALL, INTERSECT, and EXCEPT
  • Grouping extensions — GROUPING SETS, ROLLUP, and CUBE
  • Exact aggregates — MEDIAN, PERCENTILE_CONT, ARRAY_AGG, and STRING_AGG

Examples

Rank rows with a window function

SELECT customer_id, region,
       ROW_NUMBER() OVER (PARTITION BY region ORDER BY total_amount DESC) AS rank_in_region
FROM my_namespace.sales_data

Filter with QUALIFY

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Alle Routen auf einer Seite im Dashboard verwalten

Die Routes-Seite im Cloudflare-Dashboard zeigt jetzt Routen von Mesh, Tunnel, Cloudflare WAN und Magic Transit in einer Tabelle samt interaktiver Karte und erlaubt das Erstellen, Bearbeiten und Löschen, wobei der Next Hop bei WAN- und Magic-Transit-Routen per Connector-Name gewählt wird.

The Routes page in the Cloudflare dashboard now shows the routes across all of your connectors — Cloudflare Mesh and Cloudflare Tunnel routes alongside Cloudflare WAN and Magic Transit static routes — in a single table, instead of a separate routes view per product.

The unified Routes page in the Cloudflare dashboard, showing routes across connectors in a single table

From the unified Routes page you can:

  • Visualize your network with an interactive map that shows how your destinations flow through to your connectors — including equal-cost multi-path (ECMP) routes where the same prefix is served by several connectors. Select a node to filter the table down to the routes behind it.
  • See every route in one table, with its destination, type, connector, priority, and source, and filter or sort to find what you need.
  • Create, edit, and delete routes of any supported type without leaving the page. When adding a Cloudflare WAN or Magic Transit static route, you now pick the next hop by connector name instead of typing its IP. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Neue Asia-Pacific-Location-Hints: apac-ne und apac-se

Durable Objects unterstützen mit apac-ne (Nordost) und apac-se (Südost) zwei neue Location Hints für eine feinere Platzierung innerhalb von Asia-Pacific, die wie bisherige Hints als Best-Effort-Vorschlag gelten.

Durable Objects now supports two new location hints for Asia-Pacific: apac-ne (Northeast Asia-Pacific) and apac-se (Southeast Asia-Pacific). Use apac-ne or apac-se when you want finer-grained placement within Asia-Pacific rather than the broader apac hint.

Use the new hints the same way as any other locationHint:

// Northeast Asia-Pacific (Japan, Korea, etc.)
const stubNE = env.MY_DURABLE_OBJECT.get(id, { locationHint: "apac-ne" });

// Southeast Asia-Pacific (Singapore, Indonesia, etc.)
const stubSE = env.MY_DURABLE_OBJECT.get(id, { locationHint: "apac-se" });

If your users are spread across all of Asia-Pacific, the existing apac hint remains the right choice. Only reach for apac-ne or apac-se when your traffic is clearly concentrated in one sub-region and you want to minimize round-trip time to that audience. The default behavior and what we generally recommended is not adding a location hint unless absolutely needed, this will create the Durable Object as close to the initializing request as possible to reduce latency.

As with all location hints, these are best-effort suggestions. Cloudflare will place the Durable Object in a nearby data center, not necessarily the exact hinted location.

For the full list of supported hints, refer to Data location — Provide a location hint.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Ausgehende Verbindungen halten Durable Objects am Leben

Durable Objects werden nun nicht mehr evictet, solange über connect() oder einen ausgehenden WebSocket aktive Verbindungen bestehen, und erst nach deren Schließen greift das übliche Inaktivitätsfenster von 70–140 Sekunden.

Durable Objects now remain alive for the duration of active outbound connections created via connect() or an outbound WebSocket. Previously, a Durable Object would be evicted after 70-140 seconds of no incoming traffic, even if the object had an open outbound connection, which is a common pattern when streaming responses from a large language model (LLM) over TCP or an outbound WebSocket.

With this change, each active outbound connection prevents eviction. Once all outbound connections close, the standard 70-140 second inactivity window applies before the Durable Object is evicted.

Before: streaming connections were cut off by eviction

Timeline showing a Durable Object evicted 70-140 seconds after the last incoming request, cutting off an in-flight LLM stream while the outbound connection is still open

After: active outbound connections keep the Durable Object alive

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Temporäre Accounts für Deployments durch KI-Agenten

KI-Agenten können Workers nun ohne vorherige Anmeldung mit wrangler deploy --temporary (ab Wrangler 4.102.0) in einen temporären Preview-Account deployen, der 60 Minuten live bleibt und über eine Claim-URL in einen permanenten Account übernommen werden kann.

AI agents can now deploy Workers to Cloudflare without first requiring a user to sign up, open a browser-based OAuth flow, click through the dashboard, or create an API token. When an agent tries to deploy without Cloudflare credentials, Wrangler can tell it to rerun with --temporary, then deploy the Worker to a temporary preview account.

To try this with your agent, update to Wrangler 4.102.0 or later, make sure you are logged out (wrangler logout), and then ask your agent to build something and deploy it to Cloudflare. The agent should follow Wrangler's output and deploy using the --temporary flag.

Diagram showing an AI agent deploying, verifying, and redeploying a Worker to a temporary account, then claiming it after authentication and moving it to a permanent account

wrangler deploy --temporary

The temporary deployment stays live for 60 minutes. During that window, the agent can verify the Worker, redeploy changes, and return both the live Worker URL and claim URL. Opening the claim URL lets you sign in to or create a Cloudflare account and make the temporary account permanent. …

Originalquelle(öffnet in neuem Tab)Problem melden