Zum Inhalt springen

Cloudflare Release Notes

1.629 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Benutzerdefinierte DHCP-Optionen auf der Cloudflare One Appliance

Wenn die Cloudflare One Appliance als DHCP-Server fungiert, lassen sich nun eigene DHCP-Optionen vom Typ text, integer, hex oder ip konfigurieren, die vor der Anwendung auf der Appliance validiert werden.

When the Cloudflare One Appliance is acting as the DHCP server for a LAN, you can now configure custom DHCP options on the leases it issues. This unlocks workflows such as PXE / iPXE boot, VoIP phone provisioning, and vendor-specific client configuration.

Each option is defined by option_number, value, and one of four value types: text, integer, hex, or ip. Configurations are validated on the appliance before being applied — invalid configurations are rejected and the underlying error is returned to the API caller, so a bad option will not disrupt the live DHCP service.

For details, refer to DHCP server options.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Quellbasiertes Breakout und Priorisierung auf der Cloudflare One Appliance

Breakout- und Priorisierungsregeln der Cloudflare One Appliance können nun zusätzlich zur Ziel-Anwendung auch nach Quelle, also nach LAN-Interface oder IP-Adresse, Bereich bzw. CIDR-Block, zugeordnet werden.

Breakout and traffic prioritization rules on the Cloudflare One Appliance can now match by source in addition to destination application. You can pin breakout or priority behavior to:

  • A source LAN interface — VLANs attached to that LAN are included automatically.
  • A source IP address, range, or CIDR block.

This is the natural way to break out a guest VLAN to the local Internet, or to prioritize traffic from a specific subnet, without enumerating destination applications.

For details, refer to Breakout traffic.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Self-Service-Bereitstellung der Cloudflare One Virtual Appliance per API

Cloudflare One Virtual Appliances und ihre Lizenzschlüssel lassen sich nun direkt per API und Terraform erstellen, rotieren und löschen, wobei der Schlüssel nur einmalig bei Erstellung oder Rotation ausgegeben wird.

You can now create, rotate, and delete Cloudflare One Virtual Appliance instances and their license keys directly via the API and Terraform.

  • Create a virtual appliance and receive a license key: POST /accounts/{account_id}/magic/connectors with device.provision_license: true.
  • Rotate the license key for an existing virtual appliance: PATCH /accounts/{account_id}/magic/connectors/{connector_id} with provision_license: true. The previous key is immediately and irrevocably revoked.
  • Delete a virtual appliance to release the associated licensed device.

The license key is returned in the response only once, at create or rotate time. Copy and store it securely.

For details, refer to Configure a Cloudflare One Virtual Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

WAF-Schutz für React- und Next.js-Schwachstellen

Nach mehreren Sicherheitslücken in React Server Components und Next.js wird dringend das Update auf gepatchte Versionen (React 19.0.6, 19.1.7, 19.2.6; Next.js 15.5.16, 16.2.5) empfohlen, während bestehende Cloudflare-WAF-Regeln die neuen Denial-of-Service-Lücken standardmäßig blockieren.

Multiple security vulnerabilities were disclosed by the React team and Vercel affecting React Server Components and Next.js. These include denial of service, middleware and proxy bypass, server-side request forgery, cross-site scripting, and cache poisoning issues across a range of severity levels.

We strongly recommend updating your application and its dependencies immediately. Patched versions are available for React (react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack 19.0.6, 19.1.7, and 19.2.6) and Next.js (15.5.16 and 16.2.5).

WAF protections

Cloudflare WAF rules deployed in response to prior React Server Component CVEs (CVE-2025-55184 ↗︎ and CVE-2026-23864 ↗︎) already provide coverage for the newly disclosed denial-of-service vulnerabilities. These rules are enabled by default with a Block action for all customers using the Cloudflare Managed Ruleset, including Free plan customers using the Free Managed Ruleset.

Ruleset

Rule description

Rule ID

Default action

Cloudflare Managed Ruleset

React - DoS - CVE-2025-55184 ↗︎

2694f1610c0b471393b21aef102ec699

Block

Cloudflare Managed Ruleset …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Stream Bindings für Workers

Neue Stream-Bindings erlauben es, aus einem Worker heraus ohne authentifizierte API-Aufrufe Videos hochzuladen, Direct Uploads bereitzustellen, Videos zu verwalten und signierte URLs bzw. Playback-Tokens zu erzeugen.

You can now interact with your Stream video library using new bindings for Workers! This allows customers to upload content to Stream, provision direct uploads, manage videos, and generate signed URLs from a Worker without making authenticated API calls. We're excited to bring Stream and Workers closer together to empower more programmatic pipelines, tighter integrations, and support generative AI and inference workloads.

Use the Stream binding when you want to:

  • Upload videos from URLs or create basic direct upload links for end users
  • Generate signed playback tokens without managing signing keys
  • Manage video metadata, captions, downloads, and watermarks
  • Build video pipelines entirely within Workers

To get started, add the Stream binding to your Wrangler configuration:

{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "stream": {
    "binding": "STREAM"
  }
}
[stream]
binding = "STREAM"

Generate a video with AI and upload directly to Stream or send a URL of a file you already have:

const aiResponse = await env.AI.run(
	"google/veo-3.1",
	{
		prompt: "A dog walking next to a river",
		duration: "10s",
		aspect_ratio: "16:9",
		resolution: "1080p",
		generate_audio: true,
	},
	{
		gateway: { id: "experiments" },
	},
);

// Veo will return a URL of the generated asset.
const videoUrl = aiResponse.result.video;

// Alternative option: a video of the Austin Office mobile …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Automatisches Tracing über Durable Objects und Worker-Subrequests

Automatisches Tracing erzeugt nun einen einheitlichen Trace über Worker-zu-Worker-Subrequests, wobei Service-Binding- und Durable-Object-Aufrufe als verschachtelte Child Spans erscheinen, sofern Tracing in der Wrangler-Konfiguration aktiviert ist.

You can now get a single unified trace across Worker-to-Worker subrequests, with trace context propagating automatically. Previously, automatic tracing produced disconnected traces when a Worker called another Worker through a service binding or Durable Object.

Unified trace showing nested spans across a Durable Object subrequest and a service binding call

This means you can:

  • Follow a request through your entire Worker architecture in one trace view
  • See service binding and Durable Object calls as nested child spans instead of separate traces
  • Debug cross-Worker request flows in the Cloudflare dashboard or in an external observability platform via OpenTelemetry

Tracing must be enabled in your Wrangler configuration for traces to be recorded. Checkout Workers tracing to get started. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF-Schutz für React- und Next.js-Sicherheitslücken

Cloudflare hat WAF-Regeln aktiviert, die gegen neu offengelegte Denial-of-Service-Schwachstellen in React Server Components und Next.js schützen, und empfiehlt dringend Updates.

Multiple security vulnerabilities were disclosed by the React team and Vercel affecting React Server Components and Next.js. These include denial of service, middleware and proxy bypass, server-side request forgery, cross-site scripting, and cache poisoning issues across a range of severity levels.

We strongly recommend updating your application and its dependencies immediately. Patched versions are available for React (react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack 19.0.6, 19.1.7, and 19.2.6) and Next.js (15.5.16 and 16.2.5).

WAF protections

Cloudflare WAF rules deployed in response to prior React Server Component CVEs (CVE-2025-55184 ↗︎ and CVE-2026-23864 ↗︎) already provide coverage for the newly disclosed denial-of-service vulnerabilities. These rules are enabled by default with a Block action for all customers using the Cloudflare Managed Ruleset, including Free plan customers using the Free Managed Ruleset.

Ruleset

Rule description

Rule ID

Default action

Cloudflare Managed Ruleset

React - DoS - CVE-2025-55184 ↗︎

2694f1610c0b471393b21aef102ec699

Block

Cloudflare Managed Ruleset …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Security Center: CSV-Export und einstellbare Seitengröße für RFIs

Im Security Center können Nutzer jetzt RFI-Verläufe als CSV exportieren und die Anzahl der pro Seite angezeigten Einträge anpassen.

You can now export your Requests for Information (RFI) history to a CSV document and customize your dashboard view by choosing how many RFI records to load per page.

Why this matters

These quality-of-life updates focus on data portability and dashboard performance, allowing power users to manage high volumes of requests more efficiently:

  • The new CSV export allows you to move RFI data into external tools for custom reporting, internal auditing, or cross-referencing with other security projects without manual data entry
  • With adjustable page density, you can now choose to load more records at once (10, 25 or 50) to scan through history faster

Cloudforce One subscribers can find these new options in Cloudflare Dashboard > Application Security > Threat Intelligence > Requests for Information ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Notfall-WAF-Release gegen Next.js-Middleware-Bypass

Ein neues Notfall-Release fügt eine Regel zur Erkennung von Next.js-Middleware- und Proxy-Bypass-Versuchen über Segment-Prefetch-Routen hinzu.

This emergency release introduces a new rule to detect Next.js App Router middleware and proxy bypass attempts via segment-prefetch routes (CVE-2026-44575).

Key Findings

CVE-2026-44575: Next.js Middleware / Proxy Bypass in App Router Applications via Segment-Prefetch Routes

Successful exploitation allows unauthenticated attackers to bypass middleware or proxy-based authorization checks in affected Next.js App Router applications. This leads to unauthorized access to protected content, potential exposure of sensitive application data, and compromise of application security boundaries.

We strongly recommend upgrading to Next.js 15.5.16 or 16.2.5 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, enforce authorization in the underlying route or page logic instead of relying solely on middleware.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...e77e4a53

N/A

Next.js - Middleware Bypass via Invalid RSC Header - CVE:CVE-2026-44575

N/A

Disabled

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Media von Cloudflare

Stream-Bindings für Workers eingeführt

Cloudflare Stream bietet jetzt Bindings für Workers, mit denen Videos direkt aus einem Worker hochgeladen, verwaltet und signierte URLs generiert werden können, ohne API-Aufrufe.

Stream

You can now interact with your Stream video library using new bindings for Workers! This allows customers to upload content to Stream, provision direct uploads, manage videos, and generate signed URLs from a Worker without making authenticated API calls. We're excited to bring Stream and Workers closer together to empower more programmatic pipelines, tighter integrations, and support generative AI and inference workloads.

Use the Stream binding when you want to:

  • Upload videos from URLs or create basic direct upload links for end users
  • Generate signed playback tokens without managing signing keys
  • Manage video metadata, captions, downloads, and watermarks
  • Build video pipelines entirely within Workers

To get started, add the Stream binding to your Wrangler configuration:

{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "stream": {
    "binding": "STREAM"
  }
}
[stream]
binding = "STREAM"

Generate a video with AI and upload directly to Stream or send a URL of a file you already have:

const aiResponse = await env.AI.run(
	"google/veo-3.1",
	{
		prompt: "A dog walking next to a river",
		duration: "10s",
		aspect_ratio: "16:9",
		resolution: "1080p",
		generate_audio: true,
	},
	{
		gateway: { id: "experiments" },
	},
);

// Veo will return a URL of the generated asset.
const videoUrl = aiResponse.result.video; …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudy Summaries in PhishNet für O365

PhishNet-Nutzer sehen bei der E-Mail-Untersuchung nun KI-generierte Cloudy-Zusammenfassungen, die nicht auf Kundendaten trainiert sind und für Office 365 verfügbar sind, während Gmail bis Quartalsende folgen soll.

PhishNet users can now access Cloudy summaries directly within the email investigation experience. When reviewing a message in PhishNet, users will see an AI-generated summary that provides additional context and key details about the email.

These summaries help users quickly understand the nature of a message without needing to manually parse through headers, body content, and detection signals. Cloudy surfaces the most relevant information so users can make faster, more informed decisions about suspicious emails.

These summaries are not trained on customer data. They are generated using the outputs of our existing detection models and analysis systems.

This feature is available for PhishNet with Office 365. Support for Gmail will be available by the end of the quarter.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

IPv6-CIDR-Routen für Cloudflare Mesh

Cloudflare Mesh Nodes unterstützen nun IPv6-CIDR-Routen, sodass sowohl IPv4- als auch IPv6-Subnetze beworben und IPv6-only- oder Dual-Stack-Netzwerke erreichbar gemacht werden können.

Cloudflare Mesh nodes now support IPv6 CIDR routes. You can advertise both IPv4 and IPv6 subnets through your Mesh nodes, making IPv6-only or dual-stack private networks reachable from any enrolled device.

IPv6 CIDR routes on a Mesh node in the Cloudflare dashboard

To add an IPv6 route, follow the same steps as adding an IPv4 route — enter the IPv6 CIDR (for example, fd00::/64) when configuring the route in the dashboard ↗︎ or via the API.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Threat Events API unterstützt jetzt TAXII-Format

Die Cloudforce One Threat Events API unterstützt nun TAXII als Ausgabeformat für standardisierten automatisierten Austausch von Bedrohungsdaten.

The Cloudforce One Threat Events API now supports TAXII ↗︎ as an output format, enabling standardized, automated sharing of cyber threat intelligence with your existing security stack.

Why this matters

  • You can now ingest Cloudforce One threat data directly into your SIEM, TIP or SOAR tools that prefer TAXII-formatted streams without needing custom translation scripts.
  • By supporting the TAXII format parameter in our API, security teams can automate the synchronization of indicator data, reducing the manual overhead of updating blocklists and detection rules.
  • This alignment with industry standards ensures that your threat data remains consistent across different security ecosystems and partner integrations.

How to use it

When calling the Threat Events API, you can now specify taxii in the format query parameter:

GET /accounts/{account_id}/cloudforce_one/threat_events?format=taxii

You can find the updated documentation in the Cloudflare API Reference ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Pipelines und R2 Data Catalog jetzt in Terraform

Cloudflare Pipelines und R2 Data Catalog lassen sich mit dem Cloudflare Terraform provider v5.19.0 über vier neue Ressourcen (Data Catalog, Stream, Sink, Pipeline) als Infrastructure-as-Code verwalten.

Cloudflare Pipelines ingests streaming data via Workers or HTTP endpoints, transforms it with SQL, and writes it to R2 as Apache Iceberg tables. R2 Data Catalog manages those Iceberg tables, compaction, and compatibility with query engines like R2 SQL, Spark, and DuckDB.

You can now create and manage both products using Terraform, supported in the Cloudflare Terraform provider v5.19.0 ↗︎.

This adds four new resources that let you define your entire data pipeline as infrastructure-as-code: a data catalog, a stream for ingestion, a sink that writes to R2 Data Catalog or R2, and a pipeline that connects them with SQL.

The new Terraform resources are:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

Cache läuft jetzt auf Pingora-basierter Proxy-Architektur

Cloudflares Cache wird jetzt von einem neuen, auf Pingora basierenden Proxy betrieben, der geringere Latenz, weniger Cache-Misses und asynchrones Stale-while-Revalidate bietet.

Cloudflare's cache now runs on a new proxy built on Pingora ↗︎, the Rust-based framework that already serves a significant portion of Cloudflare's network traffic. The new proxy is faster, more memory-safe, and designed to evolve our cache architecture. It delivers immediate performance improvements and enables new caching capabilities.

What this brings

  • Lower latency: The new proxy reduces per-request overhead through improved connection reuse.
  • Reduced cache MISSes: Enhanced cache retention improves origin offload.
  • Better RFC compliance: Caching behavior more closely follows HTTP caching standards.
  • Foundation for future features: The new architecture enables upcoming improvements to cache functionality and efficiency.

New features

  • Asynchronous stale-while-revalidate: Every request returns stale content immediately while revalidation happens in the background, instead of the first request after expiry blocking on the origin. Refer to the asynchronous stale-while-revalidate changelog for details.
  • Unbuffered bypass by default: Responses that bypass cache are streamed directly to the client without buffering, reducing time-to-first-byte for uncacheable content.

Behavioral changes

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Neue Routing-Widgets in Cloudflare Radar

Radar erweitert den Routing-Bereich um Diagramme zu angekündigten IP-Bereichen nach AS auf Länderseiten und eine Zeitreihe zur RPKI-ROA-Abdeckung.

Radar

Radar is expanding its Routing section ↗︎ with two new widgets that give a deeper view into how networks announce address space and how RPKI ROA coverage evolves over time.

Top ASes by announced IP space on country pages

Country routing pages now include a Top ASes by announced IP space chart, breaking down the IPv4 and IPv6 address space announced from a country across the autonomous systems that originate it. The chart stacks the IPv4 and IPv6 views vertically, with the top contributing ASes called out by color and the remaining networks aggregated as Other.

Screenshot of the top ASes by announced IP space chart on a country routing page

RPKI ROA deployment timeseries …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF-Release erweitert Erkennung für Injection-Angriffe

Das WAF-Release fügt neue Erkennungen für XSS- und HTML-Injection sowie andere Angriffsvektoren hinzu und aktualisiert bestehende Regeln.

This week's release focuses on new detections to expand coverage across command injection, SQL injection, PHP object injection, remote code execution, and XSS attack vectors.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Continuous Rule Improvements

We are continuously refining our managed rules to provide more resilient protection and deeper insights into attack patterns. To ensure an optimal security posture, we recommend consistently monitoring the Security Events dashboard and adjusting rule actions as these enhancements are deployed.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...f0884a68

N/A

XSS, HTML Injection - Object Tag - Body (beta)

Log

Block

This is a new detection. This rule is merged into the original rule "XSS, HTML Injection - Object Tag" (ID: ...0c14e284).

Cloudflare Managed Ruleset

...ff012303

N/A

XSS, HTML Injection - Object Tag - Headers

Log

Block

This is a new detection. The rule previously known as "XSS, HTML Injection - Object Tag - Headers (beta)" is now renamed to "XSS, HTML Injection - Object Tag - Headers".

Cloudflare Managed Ruleset

...16f921d9

N/A

XSS, HTML Injection - Object Tag - URI

Log

Block …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Tastaturkürzel für das Cloudflare-Dashboard

Das Cloudflare-Dashboard unterstützt jetzt Tastaturkürzel für Navigation und Aktionen, die durch Drücken von „?“ angezeigt und in den Profileinstellungen deaktiviert werden können.

Cloudflare Fundamentals

You can now navigate, switch context, and take common actions in the Cloudflare dashboard without leaving your keyboard. Press ? anywhere to see the full list. Keyboard shortcuts can be disabled by visiting your profile settings ↗︎.

Navigate

Shortcut Action
g h Go to Home
g a Go to account overview
g z Go to zone overview
g p Go to your profile
g w Go to Workers & Pages
g o Go to Zero Trust
g b Go to billing
g 1 – g 5 Go to a recent or pinned item (by position in sidebar)
t → Move to the next tab
t ← Move to the previous tab
p → Move to the next page of a table
p ← Move to the previous page of a table

Take action

Shortcut Action
/ Open quick search
? Show keyboard shortcuts
s a Switch account
s z Switch zone
s . Star or unstar the current zone
p . Pin or unpin the current page
t s Toggle the sidebar open or closed
t m Expand or collapse all sidebar menus
t a Toggle Ask AI sidebar
d . Toggle dark mode
c u Copy the current URL
c d Copy a deep link URL

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Tastaturkürzel für das Cloudflare-Dashboard

Das Cloudflare-Dashboard unterstützt jetzt Tastaturkürzel zur Navigation und für häufige Aktionen; die vollständige Liste öffnet sich mit der Taste „?“.

You can now navigate, switch context, and take common actions in the Cloudflare dashboard without leaving your keyboard. Press ? anywhere to see the full list. Keyboard shortcuts can be disabled by visiting your profile settings ↗︎.

Navigate

Shortcut

Action

g h

Go to Home

g a

Go to account overview

g z

Go to zone overview

g p

Go to your profile

g w

Go to Workers & Pages

g o

Go to Zero Trust

g b

Go to billing

g 1 – g 5

Go to a recent or pinned item (by position in sidebar)

t →

Move to the next tab

t ←

Move to the previous tab

p →

Move to the next page of a table

p ←

Move to the previous page of a table

Take action

Shortcut

Action

/

Open quick search

?

Show keyboard shortcuts

s a

Switch account

s z

Switch zone

s .

Star or unstar the current zone

p .

Pin or unpin the current page

t s

Toggle the sidebar open or closed

t m

Expand or collapse all sidebar menus

t a

Toggle Ask AI sidebar

d .

Toggle dark mode

c u

Copy the current URL

c d

Copy a deep link URL

Originalquelle(öffnet in neuem Tab)Problem melden