Zum Inhalt springen

Cloudflare Release Notes

1.135 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Basin Pipelines: Ingest-Limit auf 1 GB/s erhöht

Jeder Basin Pipelines Stream kann jetzt bis zu 1 GB/s statt bisher 5 MB/s aufnehmen.

Basin Pipelines Basin

Each Basin Pipelines stream can now ingest up to 1 GB/s, increased from 5 MB/s.

The higher per-stream limit gives high-volume application events, telemetry, and logs more room to grow without splitting ingestion across streams solely to stay within the previous limit.

For the full list of stream, sink, and pipeline limits, refer to Basin Pipelines limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Cloudflare Basin ist allgemein verfügbar

Basin, früher Cloudflare Data Platform, ist allgemein verfügbar und bietet eine durchgängige Analytics-Plattform inklusive Basin Pipelines, die Events per SQL transformiert und in Iceberg-Tabellen oder Dateien auf R2 ablegt.

Basin Basin Pipelines Basin Catalog Basin SQL

Basin, formerly the Cloudflare Data Platform, is now generally available. Basin brings an end-to-end analytics platform to the Developer Platform, enabling you to collect data from a variety of sources, such as apps, infrastructure, devices, and other Cloudflare services, then query it to answer analytical questions.

Basin Pipelines

Basin Pipelines, formerly Cloudflare Pipelines, ingests events from Workers, HTTP endpoints, and Cloudflare Logpush. It transforms events with SQL and ingests them into Iceberg tables or files on R2. With Basin Pipelines you can:

  • Ingest application and device events through HTTP endpoints or Workers bindings.
  • Filter and reshape Cloudflare logs before storing them as Iceberg tables, Parquet, or JSON.
  • Catch schema mismatches with typed bindings and investigate dropped events in the dashboard.

Basin Catalog …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Durable Objects laufen mit ausstehenden I/O-Operationen ohne Client weiter

Durable Objects können durch ausstehende I/O-Operationen auch ohne verbundenen Client weiterlaufen, etwa wenn ein Agent nach dem Verbindungsabbruch einen Job fortsetzt.

Durable Objects

Durable Objects remain active while handling a request from a connected client. This change applies when no client is connected, such as when an agent continues a submitted job after its client disconnects.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Durable Objects: Ausstehende Aufrufe verhindern Beenden bis zu 15 Minuten

Ausstehende Service-Binding-, RPC-, fetch()- und monitor()-Aufrufe sowie waitUntil()-Promises und Timer verhindern nun für bis zu 15 Minuten pro Operation das Beenden eines Durable Object, standardmäßig ab Compatibility Date 2026-10-01 oder per Flag durable_object_io_tasks_prevent_eviction.

Pending service binding requests now keep Durable Objects running while they wait for a response. Pending calls to another Durable Object through remote procedure call (RPC) or fetch(), as well as this.ctx.container.monitor(), now also keep the Durable Object running.

Promises passed to this.ctx.waitUntil() and pending setTimeout() and setInterval() timers also receive this protection.

Previously, Cloudflare could shut down an idle Durable Object while one of these operations remained pending without a connected client. This could stop unfinished work.

This change helps you run long-running tasks such as agents. An agent can call tools through service bindings, coordinate with other Durable Objects, or wait for a container process without relying on the original client to remain connected.

Outbound fetch() requests to external services, TCP sockets, and outbound WebSockets already keep Durable Objects running.

Each pending operation prevents idle shutdown for up to 15 minutes. Starting another one later can extend the Durable Object's time in memory. The limit applies to each operation, not to the total time in memory.

Timeline of a service binding fetch, an RPC call, and monitor() each preventing eviction for up to 15 minutes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

Durable Objects bleiben bei ausstehenden Operationen im Speicher

Ausstehende Service-Binding-Anfragen, RPC- oder fetch()-Aufrufe an andere Durable Objects, this.ctx.container.monitor(), ctx.waitUntil()-Promises sowie setTimeout()/setInterval()-Timer verhindern nun für bis zu 15 Minuten pro Operation das Beenden eines inaktiven Durable Objects, standardmäßig bei einem Compatibility Date ab 2026-10-01 oder per Flag durable_object_io_tasks_prevent_eviction.

Pending service binding requests now keep Durable Objects running while they wait for a response. Pending calls to another Durable Object through remote procedure call (RPC) or fetch(), as well as this.ctx.container.monitor(), now also keep the Durable Object running.

Promises passed to this.ctx.waitUntil() and pending setTimeout() and setInterval() timers also receive this protection.

Previously, Cloudflare could shut down an idle Durable Object while one of these operations remained pending without a connected client. This could stop unfinished work.

This change helps you run long-running tasks such as agents. An agent can call tools through service bindings, coordinate with other Durable Objects, or wait for a container process without relying on the original client to remain connected.

Outbound fetch() requests to external services, TCP sockets, and outbound WebSockets already keep Durable Objects running.

Each pending operation prevents idle shutdown for up to 15 minutes. Starting another one later can extend the Durable Object's time in memory. The limit applies to each operation, not to the total time in memory.

Timeline of a service binding fetch, an RPC call, and monitor() each preventing eviction for up to 15 minutes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-10-01: Citrix NetScaler CVE-2026-88771

Eine neue Regel im Cloudflare Managed Ruleset blockiert Angriffe auf die Schwachstelle CVE-2026-88771 (unzureichende Eingabevalidierung) in Citrix NetScaler ADC und Gateway.

This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors.

Key Findings

  • CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands.

Impact

We strongly recommend that administrators apply the latest versions to fully secure origin servers. Additionally, customers should review configurations against applicable preconditions and follow standard incident response processes if signs of compromise are identified.

Detailed Rule Changes

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...827ab216

N/A

Citrix Netscaler ADC and Gateway - Improper input validation - CVE:CVE-2026-88771

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

Clef: Cloudflares erste Open-Source-Entscheidungsmodelle auf Workers AI

Mit @cf/cloudflare/clef und @cf/cloudflare/clef-flash sind die ersten vom Workers-AI-Team trainierten Modelle verfügbar, die statt Text für jede erlaubte Antwort eine Wahrscheinlichkeit zurückgeben.

Workers AI

Meet @cf/cloudflare/clef and @cf/cloudflare/clef-flash, the first models trained by the Cloudflare Workers AI team, available on Workers AI today.

Clef is a decision model, in the same family as Typesafe's Jev ↗︎. Instead of generating text, it reads an input state and a set of typed questions, then returns a probability for every allowed answer. Your agent gets a structured decision it can act on immediately, for example: route the ticket, block the request, or escalate to a human. There is no free-form output to parse and no reasoning tokens to wait for.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Account-Mitglieder können Account API Tokens selbst erstellen

Mitglieder mit der Rolle API Token Provisioning können nun Account API Tokens per Dashboard, API, Terraform oder CF CLI erstellen, wobei die Rechte auf ihre eigenen Berechtigungen begrenzt sind.

Account API token creation is no longer limited to Super Administrators. Members with the API Token Provisioning role can now create Account API tokens via the Dashboard, API, Terraform, or CF CLI, making it easier for developers and platform teams to provision credentials without depending on a Super Administrator for Account API Token Provisioning.

Creating an Account API Token via CF CLI

What's new

  • Delegated creation: Members with the API Token Provisioning role can create Account API tokens from the dashboard. Administrators can grant this role through the dashboard, API, or Terraform.
  • OAuth support for token creation: OAuth clients that request the account_api_tokens:create scope, starting with Cloudflare CLI, can create Account API tokens.
  • Account API token permissions limited to the creator’s access at creation time: Members can only create an Account API Token using the permissions they already have. For OAuth-created tokens, permissions are also limited to the scopes granted during authorization. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Fehlende Werte in Rules mit coalesce() behandeln

Die neue Funktion coalesce() gibt in Regelausdrücken das erste Argument zurück, das nicht nil ist, und dient so als Fallback.

The coalesce() function returns the first argument that is not nil. Use it to provide a fallback in rule expressions:

http.request.uri.path eq coalesce(http.request.uri.args["expected_path"][0], "/")

For details, refer to the coalesce() function reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Dynamische Werte in Rules-Ausdrücken vergleichen

Rules-Ausdrücke unterstützen nun dynamische Werte auf beiden Seiten von Gleichheits- und Ordnungsvergleichen, sodass Request-Felder oder Funktionsergebnisse miteinander verglichen werden können.

Cloudflare Rules expressions now support dynamic values on both sides of equality and ordering comparisons. You can compare request fields or function results with one another.

For example, compare the current request path with its original value:

http.request.uri.path ne raw.http.request.uri.path

For supported operators and examples, refer to Compare dynamic values.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Account-Mitglieder können Account API Tokens selbst erstellen

Mitglieder mit der Rolle API Token Provisioning können Account API Tokens nun über Dashboard, API, Terraform oder CF CLI erstellen, ohne dass ein Super Administrator nötig ist.

Cloudflare Fundamentals

Account API token creation is no longer limited to Super Administrators. Members with the API Token Provisioning role can now create Account API tokens via the Dashboard, API, Terraform, or CF CLI, making it easier for developers and platform teams to provision credentials without depending on a Super Administrator for Account API Token Provisioning.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

AI Gateway von Cloudflare

AI Gateway: Bezahlung von Inferenz per Machine Payments (Beta)

AI Gateway unterstützt in der Beta Machine Payments, womit sich ausgewählte Inferenz-Anfragen an /ai/run per x402-Protokoll aus einem Stablecoin-Wallet statt mit vorab aufgeladenem Guthaben bezahlen lassen.

AI Gateway now supports Machine Payments in beta. With Machine Payments, clients can use the x402 protocol to pay for eligible inference requests directly from a stablecoin wallet instead of maintaining a prepaid credit balance.

Machine Payments is available for the /ai/run endpoint with select open models. To request x402 payment, authenticate with a Cloudflare API token and include the Cloudflare-specific Payment-Method: x402 header:

curl -iX POST "https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/ai/run" \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Payment-Method: x402" \
  --header "Content-Type: application/json" \
  --data '{
    "model": "z-ai/glm-4.7-flash",
    "input": {
      "messages": [
        {
          "role": "user",
          "content": "What is Cloudflare?"
        }
      ]
    }
  }'

An x402-compatible client handles the payment challenge, signs an authorization from the client's wallet, and retries the request. Machine Payments currently requires customers to be based in the United States and have a credit card on file.

For prerequisites, eligible models, and transaction details, refer to Machine Payments (x402).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.8.2033.1 (Beta)

Das Beta-Release 2026.8.2033.1 des Cloudflare One Client für Windows bringt Fehlerbehebungen und Verbesserungen, etwa bei Reauthentifizierung, MTU-Handling, DNS-Zuverlässigkeit und Dienstwiederherstellung.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Fixed an issue that could briefly block traffic to split tunnel excluded resources while the client was connecting or reconnecting.
  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU.
  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • The client no longer requires the Windows WLAN AutoConfig service to be running.
  • Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Rollenbasierte Zugriffskontrolle für Browser-Isolation-Richtlinien

Isolation-Richtlinien für Browser Isolation unterstützen jetzt rollenbasierte Zugriffskontrolle über die Gateway-Rollen, einschließlich der Rolle „Zero Trust HTTP Policies Admin“ und ressourcenspezifischer Rollen.

Isolation policies support role-based access control (RBAC). Because isolation policies are Gateway HTTP policies with the Isolate action, Gateway's account-level and resource-scoped roles apply to them directly.

Use the Zero Trust HTTP Policies Admin account-level role to grant access to all HTTP policies in the account. You can also assign a resource-scoped role to let a team member manage a specific isolation policy without exposing other Gateway resources.

Policy settings such as copy/paste, file download/upload, keyboard, and printing are part of the policy object and follow the same permissions.

For setup instructions, refer to Granular permissions for Gateway.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Containers: Neue Scheduling-Policy „durable_object“ für Image und Instanz

Containers unterstützen in der Public Beta die Scheduling-Policy durable_object, mit der ein Durable Object zur Laufzeit Image und Instanzgröße eines Containers wählt.

Containers now support the durable_object scheduling policy in public beta. This policy lets a Durable Object select the image and instance size for a Container at runtime instead of using one centrally managed configuration for the application.

To use custom images, configure the policy and one or more named images in Wrangler:

{
	"containers": [
		{
			"class_name": "AgentComputer",
			"scheduling_policy": "durable_object",
			"images": {
				"base": {
					"dockerfile": "./container/Dockerfile",
				},
			},
		},
	],
}
[[containers]]
class_name = "AgentComputer"
scheduling_policy = "durable_object"

[containers.images.base]
dockerfile = "./container/Dockerfile"

Wrangler prepares each image and exposes its immutable reference through ctx.container.images. Supply that reference and an instance size when you start the Container:

src/index.jsjs

this.ctx.container.start({
	image: this.ctx.container.images.base,
	enableInternet: false,
	instance: "standard-2",
});

src/index.tsts

this.ctx.container.start({
	image: this.ctx.container.images.base,
	enableInternet: false,
	instance: "standard-2",
});
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Containers: Snapshots und Wiederherstellung des Dateisystems

Containers bieten in der Public Beta Snapshot-APIs, mit denen sich der Dateisystemzustand sichern und über start() wiederherstellen lässt.

Containers now support snapshot APIs in public beta for saving and restoring point-in-time filesystem state. Create a snapshot first, then pass it back to start() to restore files after container sleep, restart, or handoff to another Durable Object.

Use snapshotContainer() through the Durable Object Container API to capture the full container filesystem. Create a snapshot from a running Container, store its handle, and pass that handle to start() when you restore it later:

src/index.jsjs

import { DurableObject } from "cloudflare:workers";

export class MyDurableObject extends DurableObject {
	async saveSnapshot() {
		// Create a snapshot from the running Container.
		const containerSnapshot = await this.ctx.container.snapshotContainer({});

		await this.ctx.storage.put("containerSnapshot", containerSnapshot);
	}

	async restoreSnapshot() {
		// Restore the saved snapshot later.
		const containerSnapshot = await this.ctx.storage.get("containerSnapshot");

		if (!containerSnapshot) {
			return;
		}

		this.ctx.container.start({ containerSnapshot, enableInternet: false });
	}
}

src/index.tsts

import { DurableObject } from "cloudflare:workers";

export class MyDurableObject extends DurableObject {
	async saveSnapshot() {
		// Create a snapshot from the running Container. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Sandbox SDK 1.0: Sandboxes aus dem eigenen Durable Object steuern

Sandbox SDK 1.0 ermöglicht es, jeden Sandbox-Container direkt aus der eigenen Durable-Object-Klasse zu steuern, einschließlich Image-Wahl, Snapshots, Stoppzeitpunkt, Befehlen, Previews und ausgehenden Anfragen.

Sandbox SDK 1.0 is available. Your own Durable Object class now controls each sandbox container directly, through the Durable Object container API on this.ctx.container.

With 1.0, your class can:

  • Choose the image and instance size each time it starts a sandbox. One class can run sandboxes on different images, and a deploy does not restart sandboxes that are running.
  • Save the files of a sandbox as a snapshot, in public beta, and start the same sandbox or a new one from it.
  • Decide when each sandbox stops, for example when a task finishes, when its user goes idle, or after it saves a snapshot.
  • Run commands with streamed input and output, send them signals, and open terminals.
  • Serve previews from ports in the sandbox, with your own hostnames and authentication.
  • Handle outbound requests for each hostname in Worker code, so credentials and bindings stay in your Worker.
  • Expose only the methods that you want callers to use. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Gateway: KI-Inferenz per Machine Payments bezahlen

AI Gateway unterstützt in der Beta Machine Payments über das x402-Protokoll, sodass geeignete /ai/run-Anfragen mit ausgewählten offenen Modellen per Stablecoin-Wallet statt per Guthaben bezahlt werden können.

AI Gateway now supports Machine Payments in beta. With Machine Payments, clients can use the x402 protocol to pay for eligible inference requests directly from a stablecoin wallet instead of maintaining a prepaid credit balance.

Machine Payments is available for the /ai/run endpoint with select open models. To request x402 payment, authenticate with a Cloudflare API token and include the Cloudflare-specific Payment-Method: x402 header:

curl -iX POST "https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/ai/run" \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Payment-Method: x402" \
  --header "Content-Type: application/json" \
  --data '{
    "model": "z-ai/glm-4.7-flash",
    "input": {
      "messages": [
        {
          "role": "user",
          "content": "What is Cloudflare?"
        }
      ]
    }
  }'

An x402-compatible client handles the payment challenge, signs an authorization from the client's wallet, and retries the request. Machine Payments currently requires customers to be based in the United States and have a credit card on file.

For prerequisites, eligible models, and transaction details, refer to Machine Payments (x402).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Realtime SFU WebSocket-Adapter allgemein verfügbar

Der WebSocket-Adapter der Realtime SFU ist allgemein verfügbar und liefert Audio als PCM und Video als JPEG-Frames an beliebige WebSocket-Server wie Durable Objects.

The WebSocket adapter for Cloudflare's Realtime SFU is now generally available. The SFU (selective forwarding unit) is managed WebRTC infrastructure for live audio, video, and data across Cloudflare's global network in 330+ cities ↗︎.

The adapter connects live calls to any server that accepts WebSockets, such as a Durable Object. It delivers uncompressed pulse-code modulation (PCM) audio and JPEG video frames. Your backend can process this media without implementing a WebRTC client.

What you can build

  • Transcribe or record call audio, or let a voice agent hear and respond to participants. The AI audio example uses Durable Objects and Workers AI for transcription and speech generation. Separate adapters receive PCM audio and send generated speech back to participants.
  • Analyze images or build previews from live video. The WebRTC-to-JPEG example ↗︎ sends a browser's camera stream to a Durable Object as JPEG frames at one frame per second by default.

What changes for existing integrations

…

Originalquelle(öffnet in neuem Tab)Problem melden