Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Container-Instanzen mit wrangler containers instances auflisten

Der neue Befehl wrangler containers instances listet alle Instanzen einer Container-Anwendung mit ID, Name, Status, Standort, Version und Erstellungszeit auf und unterstützt die Ausgabe per --json.

A new wrangler containers instances command lists all instances for a given Container application. This mirrors the instances view in the Cloudflare dashboard.

The command displays each instance's ID, name, state, location, version, and creation time:

wrangler containers instances <APPLICATION_ID>

Use the --json flag for machine-readable output, which is also the default format in non-interactive environments such as CI pipelines.

For the full list of options, refer to the containers instances command reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update mit neuen Erkennungen für Ivanti und XSS

Die neue WAF-Version erkennt Schwachstellen in Ivanti Endpoint Manager Mobile sowie generische XSS-Angriffe im Content-Security-Policy-Header.

This week's release introduces new detections for vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340), alongside a new generic detection rule designed to identify and block Cross-Site Scripting (XSS) injection attempts within the Content-Security-Policy (CSP) HTTP request header.

Key Findings

  • CVE-2026-1281 & CVE-2026-1340: Ivanti Endpoint Manager Mobile processes HTTP requests through Apache RevwriteMap directives that pass user-controlled input to Bash scripts (/mi/bin/map-appstore-url and /mi/bin/map-aft-store-url). Bash scripts do not sanitize user input and are vulnerable to shell arithmetic expansion thereby allowing attackers to achieve unauthenticated remote code execution.
  • Generic XSS in CSP Header: This rule identifies malicious payloads embedded within the request's Content-Security-Policy header. It specifically targets scenarios where web frameworks or applications trust and extract values directly from the CSP header in the incoming request without sufficient validation. Attackers can provide crafted header values to inject scripts or malicious directives that are subsequently processed by the server.

Impact …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Retry-After-Header für wiederholbare 1xxx-Fehler

Cloudflare-1xxx-Fehlerantworten enthalten jetzt einen standardmäßigen Retry-After-HTTP-Header, wenn der Fehler wiederholbar ist; sieben Fehlercodes sind betroffen.

Cloudflare-generated 1xxx error responses now include a standard Retry-After HTTP header when the error is retryable. Agents and HTTP clients can read the recommended wait time from response headers alone — no body parsing required.

Changes

Seven retryable error codes now emit Retry-After:

Error code

Retry-After (seconds)

Error name

1004

120

DNS resolution error

1005

120

Banned zone

1015

30

Rate limited

1033

120

Argo Tunnel error

1038

60

HTTP headers limit exceeded

1200

60

Cache connection limit

1205

5

Too many redirects

The header value matches the existing retry_after body field in JSON and Markdown responses.

If a WAF rate limiting rule has already set a dynamic Retry-After value on the response, that value takes precedence.

Availability

Available for all zones on all plans.

Verify

Check for the header on any retryable error:

curl -s --compressed -D - -o /dev/null -H "Accept: application/json" -A "TestAgent/1.0" -H "Accept-Encoding: gzip, deflate" "<YOUR_DOMAIN>/cdn-cgi/error/1015" | grep -i retry-after

References:

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

NVIDIA Nemotron 3 Super jetzt auf Workers AI verfügbar

Workers AI bietet jetzt das Modell @cf/nvidia/nemotron-3-120b-a12b an, ein Mixture-of-Experts-Modell mit hybrider Mamba-transformer-Architektur, Tool Calling, Multi-Token Prediction und 32.000-Token-Kontextfenster, wobei der Header x-session-affinity Prompt Caching ermöglicht.

We're excited to partner with NVIDIA to bring @cf/nvidia/nemotron-3-120b-a12b to Workers AI. NVIDIA Nemotron 3 Super is a Mixture-of-Experts (MoE) model with a hybrid Mamba-transformer architecture, 120B total parameters, and 12B active parameters per forward pass.

The model is optimized for running many collaborating agents per application. It delivers high accuracy for reasoning, tool calling, and instruction following across complex multi-step tasks.

Key capabilities:

  • Hybrid Mamba-transformer architecture delivers over 50% higher token generation throughput compared to leading open models, reducing latency for real-world applications
  • Tool calling support for building AI agents that invoke tools across multiple conversation turns
  • Multi-Token Prediction (MTP) accelerates long-form text generation by predicting several future tokens simultaneously in a single forward pass
  • 32,000 token context window for retaining conversation history and plan states across multi-step agent workflows

Prompt caching

For optimal performance with multi-turn conversations, send the x-session-affinity header with a unique session identifier to enable prompt caching. This routes requests to the same model instance, reducing latency and inference costs. For details, refer to Prompt caching. …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

JSON-Antworten nach RFC 9457 für 1xxx-Fehler

Cloudflare-1xxx-Fehler liefern bei JSON-Accept-Headern strukturierte Antworten nach RFC 9457; das Markdown-Feld http_status wurde in status umbenannt.

Cloudflare-generated 1xxx errors now return structured JSON when clients send Accept: application/json or Accept: application/problem+json. JSON responses follow RFC 9457 (Problem Details for HTTP APIs) ↗︎, so any HTTP client that understands Problem Details can parse the base members without Cloudflare-specific code.

Breaking change

The Markdown frontmatter field http_status has been renamed to status. Agents consuming Markdown frontmatter should update parsers accordingly.

Changes

JSON format. Clients sending Accept: application/json or Accept: application/problem+json now receive a structured JSON object with the same operational fields as Markdown frontmatter, plus RFC 9457 standard members.

RFC 9457 standard members (JSON only):

  • type — URI pointing to Cloudflare documentation for the specific error code
  • status — HTTP status code (matching the response status)
  • title — short, human-readable summary
  • detail — human-readable explanation specific to this occurrence
  • instance — Ray ID identifying this specific error occurrence

Field renames:

  • http_status -> status (JSON and Markdown)
  • what_happened -> detail (JSON only — Markdown prose sections are unchanged) …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Log Explorer: Feldauswahl bei der Ingestierung

Log Explorer erlaubt jetzt die Auswahl der beim Aktivieren oder Verwalten von Log-Datensätzen zu ingestierenden Felder.

Cloudflare Log Explorer now allows you to customize exactly which data fields are ingested and stored when enabling or managing log datasets.

Previously, ingesting logs often meant taking an "all or nothing" approach to data fields. With Ingest Field Selection, you can now choose from a list of available and recommended fields for each dataset. This allows you to reduce noise, focus on the metrics that matter most to your security and performance analysis, and manage your data footprint more effectively.

Key capabilities

  • Granular control: Select only the specific fields you need when enabling a new dataset.
  • Dynamic updates: Update fields for existing, already enabled logstreams at any time.
  • Historical consistency: Even if you disable a field later, you can still query and receive results for that field for the period it was captured.
  • Data integrity: Core fields, such as Timestamp, are automatically retained to ensure your logs remain searchable and chronologically accurate.

Example configuration

When configuring a dataset via the dashboard or API, you can define a specific set of fields. The Timestamp field remains mandatory to ensure data indexability.

{
  "dataset": "firewall_events",
  "enabled": true,
  "fields": [
    "Timestamp",
    "ClientRequestHost",
    "ClientIP",
    "Action",
    "EdgeResponseStatus",
    "OriginResponseStatus"
  ]
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für macOS 2026.3.566.1 (Beta)

Das Beta-Release des WARP client für macOS bringt eine neue Oberfläche mit Button statt Schalter und einklappbarer Navigationsleiste sowie mehrere Fehlerbehebungen, etwa bei leeren MDM-Dateien, Proxy-Mode-Hängern und dem Wechsel zwischen Organisationen.

A new Beta release for the macOS WARP client is now available on the beta releases downloads page.

This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the Cloudflare Community forum and let us know.

Changes and improvements

  • Empty MDM files are now rejected instead of being incorrectly accepted as a single MDM config.
  • Fixed an issue in proxy mode where the client could become unresponsive due to upstream connection timeouts.
  • Fixed emergency disconnect state from a previous organization incorrectly persisting after switching organizations.
  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für Windows 2026.3.566.1 (Beta)

Das Beta-Release des WARP client für Windows bringt eine neue Oberfläche, Cubic als Congestion-Control-Algorithmus für den Tunnel, zusätzliche QUIC-Metriken in Diagnoseprotokollen sowie Fehlerbehebungen bei Paketmitschnitt und RDP-Registrierungen im Multi-User-Modus.

A new Beta release for the Windows WARP client is now available on the beta releases downloads page.

This release contains minor fixes and introduces a brand new visual style for the client interface. The new Cloudflare One Client interface changes connectivity management from a toggle to a button and brings useful connectivity settings to the home screen. The redesign also introduces a collapsible navigation bar. When expanded, more client information can be accessed including connectivity, settings, and device profile information. If you have any feedback or questions, visit the Cloudflare Community forum and let us know.

Changes and improvements

  • Consumer-only CLI commands are now clearly distinguished from Zero Trust commands.
  • Added detailed QUIC connection metrics to diagnostic logs for better troubleshooting.
  • Added monitoring for tunnel statistics collection timeouts.
  • Switched tunnel congestion control algorithm to Cubic for improved reliability across platforms.
  • Fixed packet capture failing on tunnel interface when the tunnel interface is renamed by SCCM VPN boundary support.
  • Fixed unnecessary registration deletion caused by RDP connections in multi-user mode. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Browser Run: Ganze Websites per /crawl-Endpoint crawlen

Der neue /crawl-Endpoint von Browser Rendering (Open Beta) durchsucht ab einer Start-URL automatisch eine ganze Website, rendert die Seiten und liefert sie asynchron als HTML, Markdown oder strukturiertes JSON, wobei robots.txt und AI Crawl Control standardmäßig beachtet werden.

Edit: this post has been edited to clarify crawling behavior with respect to site guidance.

You can now crawl an entire website with a single API call using Browser Rendering's new /crawl endpoint, available in open beta. Submit a starting URL, and pages are automatically discovered, rendered in a headless browser, and returned in multiple formats, including HTML, Markdown, and structured JSON. The endpoint is a verified bot (intermediary agent) that respects robots.txt and AI Crawl Control ↗︎ by default, making it easy for developers to comply with website rules, and making it less likely for crawlers to ignore web-owner guidance. This is great for training models, building RAG pipelines, and researching or monitoring content across a site.

Crawl jobs run asynchronously. You submit a URL, receive a job ID, and check back for results as pages are processed.

# Initiate a crawl
curl -X POST 'https://api.cloudflare.com/client/v4/accounts/{account_id}/browser-rendering/crawl' \
  -H 'Authorization: Bearer <apiToken>' \
  -H 'Content-Type: application/json' \
  -d '{
    "url": "https://blog.cloudflare.com/"
  }'

# Check results …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Audit Logs v2 allgemein verfügbar

Audit Logs v2 ist jetzt allgemein verfügbar und bietet standardisierte Protokollierung für etwa 95 % der Cloudflare-Produkte, erweiterte Filterung und 18 Monate Aufbewahrung.

Audit Logs v2 is now generally available to all Cloudflare customers.

Audit Logs v2 GA

Audit Logs v2 provides a unified and standardized system for tracking and recording all user and system actions across Cloudflare products. Built on Cloudflare's API Shield / OpenAPI gateway, logs are generated automatically without requiring manual instrumentation from individual product teams, ensuring consistency across ~95% of Cloudflare products.

What's available at GA:

  • Standardized logging — Audit logs follow a consistent format across all Cloudflare products, making it easier to search, filter, and investigate activity.
  • Expanded product coverage — ~95% of Cloudflare products covered, up from ~75% in v1.
  • Granular filtering — Filter by actor, action type, action result, resource, raw HTTP method, zone, and more. Over 20 filter parameters available via the API.
  • Enhanced context — Each log entry includes authentication method, interface (API or dashboard), Cloudflare Ray ID, and actor token details.
  • 18-month retention — Logs are retained for 18 months. Full history is accessible via the API or Logpush.

Access:

  • Dashboard: Go to Manage Account > Audit Logs. Audit Logs v2 is shown by default.
  • API: GET https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/audit …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

API-Shield-Vulnerability-Scanner in offener Beta

Cloudflare startet die offene Beta des Web and API Vulnerability Scanners für API-Shield-Kunden zur Erkennung von BOLA-Schwachstellen.

Introducing Cloudflare's Web and API Vulnerability Scanner (Open Beta)

Cloudflare is launching the Open Beta of the Web and API Vulnerability Scanner ↗︎ for all API Shield customers. This new, stateful Dynamic Application Security Testing (DAST) platform helps teams proactively find logic flaws in their APIs.

The initial release focuses on detecting Broken Object Level Authorization (BOLA) vulnerabilities by building API call graphs to simulate attacker and owner contexts, then testing these contexts by sending real HTTP requests to your APIs.

The scanner is now available via the Cloudflare API. To scan, set up your target environment, owner and attacker credentials, and upload your OpenAPI file with response schemas. The scanner will be available in the Cloudflare dashboard in a future release.

Access: This feature is only available to API Shield subscribers via the Cloudflare API. We hope you will use the API for programmatic integration into your CI/CD pipelines and security dashboards.

Documentation: Refer to the developer documentation to start scanning your endpoints today.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Neues MCP-Portal-Logs-Dataset und neue Felder

Cloudflare hat ein neues MCP-Portal-Logs-Dataset sowie neue Felder in mehreren bestehenden Logpush-Datasets hinzugefügt.

Cloudflare has added new fields across multiple Logpush datasets:

New dataset

  • MCP Portal Logs: A new dataset with fields including ClientCountry, ClientIP, ColoCode, Datetime, Error, Method, PortalAUD, PortalID, PromptGetName, ResourceReadURI, ServerAUD, ServerID, ServerResponseDurationMs, ServerURL, SessionID, Success, ToolCallName, UserEmail, and UserID.

New fields in existing datasets

  • DEX Application Tests: HTTPRedirectEndMs, HTTPRedirectStartMs, HTTPResponseBody, and HTTPResponseHeaders.
  • DEX Device State Events: ExperimentalExtra.
  • Firewall Events: FraudUserID.
  • Gateway HTTP: AppControlInfo and ApplicationStatuses.
  • Gateway DNS: InternalDNSDurationMs.
  • HTTP Requests: FraudEmailRisk, FraudUserID, and PayPerCrawlStatus.
  • Network Analytics Logs: DNSQueryName, DNSQueryType, and PFPCustomTag.
  • WARP Toggle Changes: UserEmail.
  • WARP Config Changes: UserEmail.
  • Zero Trust Network Session Logs: SNI.

For the complete field definitions for each dataset, refer to Logpush datasets.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workflows: Retry-Versuchsnummer im Step-Kontext verfügbar

In step.do() ist über ctx.attempt jetzt die Nummer des aktuellen Wiederholungsversuchs (1-basiert) abrufbar, etwa für Logging, progressives Backoff oder bedingte Logik.

Cloudflare Workflows allows you to configure specific retry logic for each step in your workflow execution. Now, you can access which retry attempt is currently executing for calls to step.do():

await step.do("my-step", async (ctx) => {
	// ctx.attempt is 1 on first try, 2 on first retry, etc.
	console.log(`Attempt ${ctx.attempt}`);
});

You can use the step context for improved logging & observability, progressive backoff, or conditional logic in your workflow definition.

Note that the current attempt number is 1-indexed. For more information on retry behavior, refer to Sleeping and Retrying.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

RealtimeKit: Echtzeit-Transkription in 10 Sprachen mit Varianten

Die Echtzeit-Transkription in RealtimeKit unterstützt über Deepgram Nova-3 auf Workers AI nun 10 Sprachen mit regionalen Varianten, einstellbar über ai_config.transcription.language, und die Audioverarbeitung läuft durchgehend im Cloudflare-Netzwerk.

Real-time transcription in RealtimeKit now supports 10 languages with regional variants, powered by Deepgram Nova-3 running on Workers AI.

During a meeting, participant audio is routed through AI Gateway to Nova-3 on Workers AI — so transcription runs on Cloudflare's network end-to-end, reducing latency compared to routing through external speech-to-text services.

Set the language when creating a meeting via ai_config.transcription.language:

{
	"ai_config": {
		"transcription": {
			"language": "fr"
		}
	}
}

Supported languages include English, Spanish, French, German, Hindi, Russian, Portuguese, Japanese, Italian, and Dutch — with regional variants like en-AU, en-GB, en-IN, en-NZ, es-419, fr-CA, de-CH, pt-BR, and pt-PT. Use multi for automatic multilingual detection.

If you are building voice agents or real-time translation workflows, your agent can now transcribe in the caller's language natively — no extra services or routing logic needed.

Originalquelle(öffnet in neuem Tab)Problem melden

Consumer Services von Cloudflare

Regionenfilter, AS-Traffic-Volumen und Navigation auf Cloudflare Radar

Cloudflare Radar unterstützt jetzt das Filtern nach Regionen und zeigt das Verkehrsvolumen der wichtigsten autonomen Systeme und Standorte an.

Radar

Radar ships several new features that improve the flexibility and usability of the platform, as well as visibility into what is happening on the Internet.

Region filtering

All location-aware pages now support filtering by region, including continents, geographic subregions (Middle East ↗︎, Eastern Asia ↗︎, etc.), political regions (EU ↗︎, African Union ↗︎), and US Census regions/divisions (for example, New England ↗︎, US Northeast ↗︎).

Screenshot of region filtering on Radar - Middle east

Traffic volume by top autonomous systems and locations

A new traffic volume view shows the top autonomous systems and countries/territories for a given location. This is useful for quickly determining which network providers in a location may be experiencing connectivity issues, or how traffic is distributed across a region. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Brand Protection: Treffer verwerfen und filtern

Im Security Center können Brand-Protection-Treffer jetzt als verworfen markiert und über einen Ein-/Ausblenden-Schalter ausgeblendet oder wieder angezeigt werden.

We have introduced new triage controls to help you manage your Brand Protection results more efficiently. You can now clear out the noise by dismissing matches while maintaining full visibility into your historical decisions.

What's new

  • Dismiss matches: Users can now mark specific results as dismissed if they are determined to be benign or false positives, removing them from the primary triage view.
  • Show/Hide toggle: A new visibility control allows you to instantly switch between viewing only active matches and including previously dismissed ones.
  • Persistent review states: Dismissed status is saved across sessions, ensuring that your workspace remains organized and focused on new or high-priority threats.

Key benefits of the dismiss match functionality:

  • Reduce alert fatigue by hiding known-safe results, allowing your team to focus exclusively on unreviewed or high-risk infringements.
  • Auditability and recovery through the visibility toggle, ensuring that no match is ever truly "lost" and can be re-evaluated if a site's content changes.
  • Improved collaboration as your team members can see which matches have already been vetted and dismissed by others.

Ready to clean up your match queue? Learn more in our Brand Protection documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Media von Cloudflare

Echtzeit-Transkription unterstützt 10 Sprachen

Die Echtzeit-Transkription in RealtimeKit unterstützt jetzt 10 Sprachen mit regionalen Varianten über Deepgram Nova-3 auf Workers AI.

Workers AI Realtime

Real-time transcription in RealtimeKit now supports 10 languages with regional variants, powered by Deepgram Nova-3 running on Workers AI.

During a meeting, participant audio is routed through AI Gateway to Nova-3 on Workers AI — so transcription runs on Cloudflare's network end-to-end, reducing latency compared to routing through external speech-to-text services.

Set the language when creating a meeting via ai_config.transcription.language:

{
	"ai_config": {
		"transcription": {
			"language": "fr"
		}
	}
}

Supported languages include English, Spanish, French, German, Hindi, Russian, Portuguese, Japanese, Italian, and Dutch — with regional variants like en-AU, en-GB, en-IN, en-NZ, es-419, fr-CA, de-CH, pt-BR, and pt-PT. Use multi for automatic multilingual detection.

If you are building voice agents or real-time translation workflows, your agent can now transcribe in the caller's language natively — no extra services or routing logic needed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

User Risk Score als Selektor in Access-Richtlinien

In Access-Richtlinien lässt sich jetzt der Selektor User Risk Score verwenden, um auf erkannte Verhaltensmuster wie Impossible Travel oder viele DLP-Treffer zu reagieren.

You can now use user risk scores in your Access policies. The new User Risk Score selector allows you to create Access policies that respond to user behavior patterns detected by Cloudflare's risk scoring system, including impossible travel, high DLP policy matches, and more.

For more information, refer to Use risk scores in Access policies.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway Authorization Proxy und gehostete PAC-Dateien (Open Beta)

Der Gateway Authorization Proxy und das Hosting von PAC-Dateien sind für alle Tarife in der Open Beta und ersetzen die IP-basierte Autorisierung durch Cloudflare-Access-Authentifizierung, ohne dass der WARP client nötig ist.

The Gateway Authorization Proxy and PAC file hosting are now in open beta for all plan types.

Previously, proxy endpoints relied on static source IP addresses to authorize traffic, providing no user-level identity in logs or policies. The new authorization proxy replaces IP-based authorization with Cloudflare Access authentication, verifying who a user is before applying Gateway filtering without installing the WARP client.

This is ideal for environments where you cannot deploy a device client, such as virtual desktops (VDI), mergers and acquisitions, or compliance-restricted endpoints.

Key capabilities

…

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Browser Rendering: 3-fach höhere REST-API-Rate

Das Rate Limit der Browser Rendering REST API für Workers-Paid-Pläne wurde von 3 auf 10 Anfragen pro Sekunde (600 pro Minute) erhöht, ohne dass Nutzer etwas tun müssen.

Browser Rendering REST API rate limits for Workers Paid plans have been increased from 3 requests per second (180/min) to 10 requests per second (600/min). No action is needed to benefit from the higher limit.

Browser Rendering REST API rate limit increased from 3 to 10 requests per second

The REST API lets you perform common browser tasks with a single API call, and you can now do it at a higher rate.

Originalquelle(öffnet in neuem Tab)Problem melden