Zum Inhalt springen

Cloudflare Release Notes

1.629 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workflows in Dynamic Workers mit @cloudflare/dynamic-workflows

Die Bibliothek @cloudflare/dynamic-workflows ermöglicht es, Workflows innerhalb von Dynamic Workers dauerhaft auszuführen, indem sie Workflow-Instanzen mit Metadaten markiert und den passenden Dynamic Worker beim Fortsetzen über den Worker Loader neu lädt.

You can now use @cloudflare/dynamic-workflows ↗︎ to run a Workflow inside a Dynamic Worker, ensuring durable execution for code that is loaded at runtime.

The Worker Loader loads Dynamic Workers on demand, which previously made durability challenging. Even within a Dynamic Worker, a Workflow might sleep for hours or days between steps, and by the time it resumes, the original Dynamic Worker code would no longer be in memory.

The library solves this by tagging each Workflow instance with metadata that identifies which Dynamic Worker to load — for example, a tenant ID — then reloading the matching Dynamic Worker through the Worker Loader whenever a Workflow awakens.

Because Dynamic Workers are created on-demand, you do not have to register each Workflow up front or manage them individually. Load the Workflow code in the Dynamic Worker when it is needed, and the Workflows engine handles persistence and retries behind the scenes. Your Workflow code itself is unaffected by the routing and behaves as normal.

This unlocks patterns where the Workflow code itself is dynamic. For example, this is useful with:

  • SaaS platforms where each tenant defines their own automation, such as onboarding sequences, approval chains, or billing retry logic. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Post-Quantum-IPsec-Interoperabilität mit Drittanbieter-Geräten

Cloudflare IPsec unterstützt nun Post-Quantum-Schlüsselaustausch mit ML-KEM mit kompatiblen Geräten von Cisco (8000 Series mit IOS XR 26.1.1) und Fortinet (FortiOS 7.6.6 und neuer), ohne zusätzliche Lizenz.

Cloudflare IPsec now supports post-quantum key agreement with compatible third-party devices. Cisco ↗︎ and Fortinet ↗︎ are the first third-party vendors validated to interoperate with Cloudflare IPsec using ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).

Post-quantum IPsec uses RFC 9370 ↗︎ and draft-ietf-ipsecme-ikev2-mlkem ↗︎ to negotiate hybrid key agreement during the IKEv2 IKE_INTERMEDIATE phase. This combines classical Diffie-Hellman (Group 20) with ML-KEM-768 or ML-KEM-1024 to protect against harvest-now, decrypt-later ↗︎ attacks.

Key details:

  • Compatible with Cisco 8000 Series Secure Routers with IOS XR Release 26.1.1 and Fortinet FortiOS 7.6.6 and later.
  • Uses ML-KEM-768 or ML-KEM-1024 as an additional Key Exchange to DH Group 20.
  • Follows RFC 9370 and draft-ietf-ipsecme-ikev2-mlkem standards.
  • No additional licensing required.

Post-quantum IPsec with third-party devices is now generally available with confirmed interoperability for the platforms listed above. Cloudflare intends to support interoperability with more vendors as they build out support for draft-ietf-ipsecme-ikev2-mlkem. Contact your account team to discuss support for additional vendors. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Data Classification in Cloudflare DLP

Cloudflare DLP enthält nun Data Classification, mit der Administratoren sensible Inhalte über Labels, Vorlagen und wiederverwendbare Datenklassen organisieren und in benutzerdefinierten DLP-Profilen nutzen können.

Cloudflare DLP now includes Data Classification, which lets administrators organize and label sensitive content using labels, templates, and reusable data classes.

With Data Classification, administrators can define labels such as sensitivity schemas and levels, and data tag groups and tags. Administrators can also build from Cloudflare-managed templates and create reusable data classes that combine detection entries, other data classes, sensitivity levels, and data tags.

You can then use those classifications in custom DLP profiles to identify the severity of sensitive content, understand where it exists, and apply that logic consistently across DLP profiles.

For more information, refer to Data Classification.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue vordefinierte DLP-Erkennungseinträge

Cloudflare DLP bietet einen erweiterten Katalog vordefinierter Erkennungseinträge, etwa für Zugangsdaten, Webhooks, Adressen, Steuer- und Ausweisnummern, Finanzdaten und Krypto-Wallets, darunter GitHub PAT, OpenAI API Key und Bitcoin Wallet.

Cloudflare DLP now includes new predefined detection entries.

The expanded catalog includes detections for specific credential types, webhooks, addresses, tax identifiers, national IDs, financial data, and crypto wallets.

Examples include GitHub PAT, OpenAI API Key, Slack Webhook, Discord Webhook, US Physical Address, and Bitcoin Wallet.

For the full list, refer to Predefined detection entries.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

R2-Buckets leeren und Ordner im Dashboard löschen

Im R2-Dashboard lassen sich nun ganze Buckets mit einer Aktion leeren, was vor dem Löschen eines Buckets nötig ist, sowie einzelne oder mehrere Ordner samt aller Objekte unter dem Präfix löschen.

You can now empty an entire R2 bucket or delete folders directly from the dashboard. Emptying a bucket is required before you can delete it. Previously, this required scripting or configuring lifecycle rules. Now, the dashboard can handle it in a single action.

Empty a bucket

Go to your bucket's Settings tab and select Empty under the Empty Bucket section. This deletes all objects in the bucket while preserving the bucket and its configuration. For large buckets, the operation runs in the background and the dashboard displays progress.

Emptying a bucket is also a prerequisite for deleting it. The dashboard now guides you through both steps in one place.

Empty Bucket and Delete Bucket sections in the R2 dashboard Settings tab

Delete folders

R2 uses a flat object structure. The dashboard groups objects that share a common prefix into folders when the View prefixes as directories checkbox is selected. Deleting a folder removes every object under that prefix.

From the Objects tab, you can select one or more folders and delete them alongside individual objects. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

Speed – Shared Dictionaries Passthrough in offener Beta

Die Weitergabe von Shared Dictionaries ist jetzt in der offenen Beta für alle Tarife verfügbar, wobei Cloudflare die Header unverändert weiterleitet und Dictionary-komprimierte Antworten unterstützt.

Shared dictionaries (RFC 9842 ↗︎) let an origin compress a response against a previous version of the same resource that the browser already has cached, so only the difference between versions travels over the wire. Shared dictionaries passthrough is now in open beta on all plans.

What changed

In passthrough mode, Cloudflare:

  • Forwards the Use-As-Dictionary and Available-Dictionary headers between client and origin without modification.
  • Treats dcb (Dictionary-Compressed Brotli) and dcz (Dictionary-Compressed Zstandard) as valid Content-Encoding values end to end, without recompressing them.
  • Extends the cache key to vary on Available-Dictionary and Accept-Encoding so each delta-compressed variant is cached correctly.

Your origin manages the dictionary lifecycle: deciding which assets are dictionaries, attaching Use-As-Dictionary headers, and producing deltas in response to Available-Dictionary requests. Cloudflare handles the transport and the cache.

In internal testing on a 272 KB JavaScript bundle, the asset shrinks from 92.1 KB with Gzip to 2.6 KB with delta Zstandard against the previous version — a 97% reduction over standard compression — with download times improving by 81–89% versus Gzip. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

Web Analytics mit Navigationstyp-Filterung und -Berichten

Cloudflare Web Analytics unterstützt jetzt die Berichterstattung und Filterung nach Navigationstypen, um das Nutzerverhalten und die Leistung der Browser-Cache-Nutzung besser zu verstehen.

Cloudflare Web Analytics now supports Navigation Type reporting and filtering.

This update allows developers and performance analysts to see how users are navigating between pages — whether through a link click or form submission, a page reload, or using the browser's back/forward buttons — and whether a browser cache hit occurred for these behaviors.

Understanding navigation types is critical for optimizing user experience. For example, if a high volume of your traffic consists of "Back-forward" navigations versus "Back-forward Cache", those visitors are not benefiting from the Back/Forward Cache (bfcache) and therefore are experiencing higher load times due to potentially unnecessary network requests.

The same applies for regular "Navigate" entries — where "Navigate Cache", "Navigate Prefetch Cache" and "Prerender" would provide instant document retrieval — and "Reload", where "Reload cache" would be more optimal.

A high volume of "Reload" entries can also indicate a potential stability problem with your website.

By identifying these patterns, you can tune your browser caching strategies to ensure HTML documents are served instantaneously from local caches rather than requiring a roundtrip to the network.

For more information, refer to Navigation Types.

Key benefits

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Cloud Observatory: Verbindungsmetriken verbessert

Cloud Observatory bietet nun Verbindungsmetriken pro Cloud-Anbieter und nach Region für die fünf besten Regionen eines Anbieters.

Radar

The Cloud Observatory ↗︎ on Radar now provides improved connection metric insights, offering new ways to explore TCP round-trip time, TCP handshake duration, TLS handshake duration, and response header receive duration across cloud provider origin servers.

The Cloud Observatory overview ↗︎ now shows connection metrics broken down by cloud provider, making it easy to compare connection performance across Amazon Web Services, Google Cloud, Microsoft Azure, and Oracle Cloud.

Screenshot of Cloud Observatory connection metrics broken down by cloud provider

Each provider page ↗︎ now shows connection metrics for the top five regions, with a selector to rank by lowest or highest values.

Screenshot of Cloud Observatory connection metrics broken down by region for a provider …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Dark Mode in Cloudflare Radar

Cloudflare Radar unterstützt jetzt einen Dark Mode mit Umschalter zwischen Hell, Dunkel und Systemeinstellung.

Radar

Radar now supports dark mode. A theme selector in the upper right corner of the page lets users explicitly choose between three display options:

  • Light — standard light theme
  • Dark — full dark theme
  • System — follows the operating system preference

Screenshot of the theme selector showing Light, Dark, and System options

The selected theme applies consistently across all Radar pages and widgets.

Screenshot of the Cloudflare Radar overview page in dark mode

The theme choice also applies to shared and embedded graphs.

Try it out at Cloudflare Radar ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Notfall-WAF-Regel gegen cPanel-Authentifizierungs-Bypass

Ein Notfall-Release führt eine neue Regel ein, die einen kritischen cPanel- und WHM-Authentifizierungs-Bypass (CVE-2026-41940) blockiert.

This emergency release introduces a new rule to block a cPanel & WHM Authentication Bypass related to CVE-2026-41940.

Key Findings

  • CVE-2026-41940: A critical authentication bypass vulnerability in cPanel & WHM allows unauthenticated remote attackers to bypass authentication mechanisms and gain unauthorized administrative access to the web hosting control panel. This vulnerability affects the session validation logic, enabling attackers to craft malicious requests that circumvent normal authentication checks.

Impact

Successful exploitation allows unauthenticated attackers to gain administrative control over affected cPanel & WHM installations. This leads to complete server compromise, potential theft or manipulation of hosted data, and significant service disruption across managed environments.

We strongly recommend applying official vendor patches for cPanel & WHM immediately to address the underlying vulnerability.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...eb2b9e2f

N/A

cPanel - Auth Bypass - CVE:CVE-2026-41940

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Go SDK v7.0.0 veröffentlicht

Das Cloudflare Go SDK v7.0.0 enthält breaking changes in den Paketen ai_search, email_security und workers sowie ein Migrationspaket für die Aktualisierung.

Full Changelog: v6.10.0...v7.0.0 ↗︎

This is a major version release that includes breaking changes to three packages: ai_search, email_security, and workers. These changes reflect upstream API specification updates that improve type correctness and consistency.

Please ensure you read through the list of changes below before moving to this version - this will help you understand any down or upstream issues it may cause to your environments.

Breaking Changes

See the v7.0.0 Migration Guide ↗︎ for before/after code examples and actions needed for each change.

AI Search - SearchForAgents Metadata Removed

The SearchForAgents nested type has been removed from all instance metadata structs. This field is no longer part of the API specification.

Removed Types:

  • InstanceNewResponseMetadataSearchForAgents
  • InstanceUpdateResponseMetadataSearchForAgents
  • InstanceListResponseMetadataSearchForAgents
  • InstanceDeleteResponseMetadataSearchForAgents
  • InstanceReadResponseMetadataSearchForAgents
  • InstanceNewParamsMetadataSearchForAgents
  • InstanceUpdateParamsMetadataSearchForAgents
  • NamespaceInstanceNewResponseMetadataSearchForAgents …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Cloudflare Python SDK v5.0.0 veröffentlicht

Das Cloudflare Python SDK v5.0.0 beendet die Unterstützung für Python 3.8, fügt 11 neue API-Services und optionale aiohttp-Unterstützung hinzu und enthält zahlreiche Typ- und Methodenaktualisierungen.

Full Changelog: v4.3.1...v5.0.0 ↗︎

This is a major release of the Cloudflare Python SDK. It drops support for Python 3.8, adds 11 new API services, introduces optional aiohttp backend support for improved async concurrency, and includes hundreds of type and method updates across the entire API surface.

Please review the breaking changes below before upgrading. A migration guide is available at v5.0.0 Migration Guide ↗︎.

Breaking Changes

  • Python 3.8 is no longer supported. The minimum required version is now Python 3.9.
  • typing-extensions minimum version bumped from >=4.10 to >=4.14.

The following resources have breaking changes. See the v5.0.0 Migration Guide ↗︎ for detailed migration instructions.

  • abusereports
  • acm.totaltls
  • apigateway.configurations
  • cloudforceone.threatevents
  • d1.database
  • intel.indicatorfeeds
  • logpush.edge
  • origintlsclientauth.hostnames
  • queues.consumers
  • radar.bgp
  • rulesets.rules
  • schemavalidation.schemas
  • snippets
  • zerotrust.dlp
  • zerotrust.networks

Features

aiohttp Backend Support …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Cloudflare TypeScript SDK v6.0.0 veröffentlicht

Das Cloudflare TypeScript SDK v6.0.0 fügt 11 neue Top-Level-API-Ressourcen und Unterressourcen hinzu und ändert unter anderem die Retry-After-Behandlung und das Verhalten bei leeren Antworten.

Full Changelog: v6.0.0-beta.2...v6.0.0 ↗︎

This is a major version release of the Cloudflare TypeScript SDK. It includes 11 entirely new top-level API resources, new sub-resources and methods across 50+ existing resources, SDK infrastructure improvements, and breaking changes to the generated API surface from the v5.x line.

Please ensure you read through the list of changes below before moving to this version - this will help you understand any down or upstream issues it may cause to your environments.

Breaking Changes

SDK Infrastructure

  • Retry-After handling changed: The SDK now respects any server-specified Retry-After value for rate-limited requests. Previously, values over 60 seconds were ignored and a default backoff was used instead.
  • Empty response handling: Responses with content-length: 0 now return undefined instead of attempting to parse the body.
  • Environment variable reading: Empty string env vars (for example, CLOUDFLARE_API_TOKEN="") are now treated as unset.
  • Path query parameter merging: URL search params embedded in endpoint paths are now extracted and merged into the query object.

Removed Endpoints (17)

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX-Tests für authentifizierte Ressourcen und erweiterte Konfiguration

Digital experience tests können nun durch Cloudflare Access oder Drittanbieter-Authentifizierung geschützte Anwendungen testen, wobei Secrets über Cloudflare Secret Store verwaltet werden, und bieten zusätzliche HTTP-Methoden, Header, Request-Bodys und erweiterte Einstellungen.

Digital experience tests now support testing applications protected by Cloudflare Access or third-party authentication. All authentication secrets are managed via Cloudflare Secret Store.

Digital experience tests also have enhanced configuration options including:

  • New HTTP methods (DELETE, PATCH, POST, PUT)
  • Secret Store headers, custom plain text headers, and custom request bodies
  • Advanced settings: follow redirects, response bodies, response headers, and allow untrusted certificates

Digital experience test configuration for Cloudflare Access applicationsDigital experience enhanced test configuration

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway Authorization Proxy und gehostete PAC-Dateien allgemein verfügbar

Der Gateway Authorization Proxy und von Cloudflare gehostete PAC-Dateien sind nun für alle Tarife allgemein verfügbar und ermöglichen identitätsbasierte Gateway-Filterung ohne installierten Cloudflare One Client.

The Gateway Authorization Proxy and hosted PAC files are now generally available for all plan types.

Authorization proxy endpoints add an identity-aware option alongside the existing source IP proxy endpoints, using Cloudflare Access authentication to verify who a user is before applying Gateway filtering — without installing the Cloudflare One Client. Cloudflare-hosted PAC files let you create and distribute PAC files directly from Cloudflare One on Cloudflare's global network.

These features are ideal for environments where deploying a device client is not an option, such as virtual desktops (VDI) or compliance-restricted endpoints.

To get started, refer to the proxy endpoints documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Hyperdrive unterstützt private Datenbanken über Workers VPC

Hyperdrive lässt sich jetzt über einen Workers-VPC-Service mit einer privaten, nicht öffentlich erreichbaren Datenbank verbinden, per Dashboard oder über wrangler hyperdrive create.

You can now connect Hyperdrive to a private database through a Workers VPC service. This is the recommended way to connect Hyperdrive to a private database that is not exposed to the public Internet.

When creating a Hyperdrive configuration in the Cloudflare dashboard, choose Connect to private database and then Workers VPC. From there, you can select an existing VPC service or create a new one inline by picking a Cloudflare Tunnel and entering your origin host and TCP port.

You can also create a Hyperdrive configuration backed by a Workers VPC service from the command line:

npx wrangler hyperdrive create my-vpc-database \
  --service-id <YOUR_VPC_SERVICE_ID> \
  --database <DATABASE_NAME> \
  --user <DATABASE_USER> \
  --password <DATABASE_PASSWORD> \
  --scheme postgresql

Workers VPC services are reusable across Hyperdrive configurations and can also be bound directly to Workers, so you can share the same private connection across multiple products.

To get started, refer to Connect Hyperdrive to a private database using Workers VPC.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Sofortige Bankzahlungen über Link

Cloudflare akzeptiert nun Sofortbankzahlungen über Link neben Kartenzahlungen, wobei gespeicherte Bankkonten als Zahlungsoption erscheinen.

Cloudflare Fundamentals

You can now pay for Cloudflare services directly from your bank account using Instant Bank Payments via Link.

What changed

Link ↗︎ now supports bank account payments in addition to cards. If you have a bank account saved in Link, it appears as a payment option at checkout. If not, you can connect one during the checkout flow.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Sofortige Bankzahlungen über Link

US-basierte Self-Serve-Konten können Cloudflare-Services jetzt direkt per Bankkonto über Link bezahlen; gespeicherte Bankkonten erscheinen beim Checkout als Zahlungsoption.

You can now pay for Cloudflare services directly from your bank account using Instant Bank Payments via Link.

What changed

Link ↗︎ now supports bank account payments in addition to cards. If you have a bank account saved in Link, it appears as a payment option at checkout. If not, you can connect one during the checkout flow.

Instant Bank Payments via Link at checkout

How to use it

  1. During checkout, select your bank account from your saved Link payment methods.
  2. Confirm the payment.

After your first Link authentication, your bank account is available for future purchases without re-entering details.

Who is eligible

Instant Bank Payments via Link is available to US-based self-serve accounts across all Cloudflare products. Your existing cards remain available at checkout.

Bank-based Link payments appear in your billing history with the payment method shown as link and last four digits as 0000. For details, refer to the Instant Bank Payments via Link documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX: Benachrichtigungen bei Internet-Ausfällen für Geräte

Digital Experience zeigt nun eine Dashboard-Benachrichtigung an, wenn ein Internet-Ausfall oder eine Traffic-Anomalie ein Cloudflare-One-Client-Gerät aufgrund von Standort oder Netzwerkverbindung betreffen könnte, basierend auf Daten von Cloudflare Radar.

Digital Experience will display a dashboard notification when an Internet outage or traffic anomaly may impact a Cloudflare One Client device based on its geographic location or network connection.

This Internet outage and traffic anomaly data is pulled from Cloudflare Radar ↗︎. All Internet outage and traffic anomaly observations can be viewed in the Radar Outage Center ↗︎.

Digital Experience Monitoring dashboard notification for Internet outage impacting Cloudflare One Client devicesDigital Experience Monitoring dashboard analytics for Internet outage impacting Cloudflare One Client devices

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX: Speed-Tests vom Cloudflare One Client

IT-Teams können nun aus der Ferne Speed-Tests vom Cloudflare One Client zum Cloudflare-Netzwerkrand ausführen, die Durchsatz, Latenz, Jitter und Netzwerkqualitätswerte liefern.

IT teams can now remotely run speed tests from the Cloudflare One Client to Cloudflare's network edge.

Each speed test includes the following metrics:

  • Internet speed: download and upload throughput
  • Latency: download, upload, unloaded latency, and jitter
  • Network quality score: video streaming, webchat/real-time communication (RTC)

In the Cloudflare dashboard ↗︎, go to Zero Trust > Insights > Digital experience > Diagnostics and select Run diagnostics to use the feature today.

Cloudflare One client speed test result

Originalquelle(öffnet in neuem Tab)Problem melden