Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Cloudflare One von Cloudflare

Post-Quantum-Verschlüsselung für Cloudflare One Appliance

Cloudflare One Appliance 2026.2.0 unterstützt Post-Quantum-Verschlüsselung mit hybridem ML-KEM über TLS 1.3 und schützt IPsec-Datenverkehr damit gegen Harvest-now-decrypt-later-Angriffe, wobei das Update automatisch in den konfigurierten Wartungsfenstern eingespielt wird.

Cloudflare One Appliance version 2026.2.0 adds post-quantum encryption support using hybrid ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).

The appliance now uses TLS 1.3 with hybrid ML-KEM for its connection to the Cloudflare edge. During the TLS handshake, the appliance and the edge share a symmetric secret over the TLS connection and inject it into the ESP layer of IPsec. This protects IPsec data plane traffic against harvest-now, decrypt-later attacks.

This upgrade deploys automatically to all appliances during their configured interrupt windows with no manual action required.

For more information, refer to Cloudflare One Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers nicht mehr auf 1000 Subrequests begrenzt

Das Limit von 1000 Subrequests pro Invocation entfällt; bezahlte Pläne erlauben standardmäßig 10.000, einstellbar bis 10 Millionen über das neue Wrangler-Limit subrequests, während der Free-Plan bei 50 externen und 1000 Cloudflare-internen Subrequests bleibt.

Workers no longer have a limit of 1000 subrequests per invocation, allowing you to make more fetch() calls or requests to Cloudflare services on every incoming request. This is especially important for long-running Workers requests, such as open websockets on Durable Objects or long-running Workflows, as these could often exceed this limit and error.

By default, Workers on paid plans are now limited to 10,000 subrequests per invocation, but this limit can be increased up to 10 million by setting the new subrequests limit in your Wrangler configuration file.

{
	"limits": {
		"subrequests": 50000,
	},
}
[limits]
subrequests = 50_000

Workers on the free plan remain limited to 50 external subrequests and 1000 subrequests to Cloudflare services per invocation.

To protect against runaway code or unexpected costs, you can also set a lower limit for both subrequests and CPU usage.

{
	"limits": {
		"subrequests": 10,
		"cpu_ms": 1000,
	},
}
[limits]
subrequests = 10
cpu_ms = 1_000

For more information, refer to the Wrangler configuration documentation for limits and subrequest limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Bessere React-Server-Components-Unterstützung im Cloudflare Vite Plugin

Das Cloudflare Vite Plugin arbeitet nun mit @vitejs/plugin-rsc zusammen und bietet die neue Option childEnvironments, um mehrere Umgebungen innerhalb eines Workers zu nutzen.

The Cloudflare Vite plugin now integrates seamlessly @vitejs/plugin-rsc ↗︎, the official Vite plugin for React Server Components ↗︎.

A childEnvironments option has been added to the plugin config to enable using multiple environments within a single Worker. The parent environment can then import modules from a child environment in order to access a separate module graph. For a typical RSC use case, the plugin might be configured as in the following example:

vite.config.tsts

export default defineConfig({
	plugins: [
		cloudflare({
			viteEnvironment: {
				name: "rsc",
				childEnvironments: ["ssr"],
			},
		}),
	],
});

@vitejs/plugin-rsc provides the lower level functionality that frameworks, such as React Router ↗︎, build upon. The GitHub repository includes a basic Cloudflare example ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Regel für Fake Google Bot deaktiviert

Die Regel zur Erkennung von falschen Google-Bots im User-Agent-Header wird von BLOCK auf Deaktiviert umgestellt.

This week’s release changes the rule action from BLOCK to Disabled for Anomaly:Header:User-Agent - Fake Google Bot.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...6aa0bef8

N/A

Anomaly:Header:User-Agent - Fake Google Bot

Enabled

Disabled

We are changing the action for this rule from BLOCK to Disabled

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.4.0: Readonly-Verbindungen, MCP-Sicherheit, x402 v2

Das Agents SDK 0.4.0 bringt schreibgeschützte WebSocket-Verbindungen, Verbesserungen bei MCP-Protokoll und Sicherheit, die Migration auf x402 v2 sowie createMcpOAuthProvider zum Anpassen der OAuth-Anbindung an MCP-Server.

The latest release of the Agents SDK ↗︎ brings readonly connections, MCP protocol and security improvements, x402 payment protocol v2 migration, and the ability to customize OAuth for MCP server connections.

Readonly connections

Agents can now restrict WebSocket clients to read-only access, preventing them from modifying agent state. This is useful for dashboards, spectator views, or any scenario where clients should observe but not mutate.

New hooks: shouldConnectionBeReadonly, setConnectionReadonly, isConnectionReadonly. Readonly connections block both client-side setState() and mutating @callable() methods, and the readonly flag survives hibernation.

class MyAgent extends Agent {
	shouldConnectionBeReadonly(connection) {
		// Make spectators readonly
		return connection.url.includes("spectator");
	}
}
class MyAgent extends Agent {
	shouldConnectionBeReadonly(connection) {
		// Make spectators readonly
		return connection.url.includes("spectator");
	}
}

Custom MCP OAuth providers

The new createMcpOAuthProvider method on the Agent class allows subclasses to override the default OAuth provider used when connecting to MCP servers. This enables custom authentication strategies such as pre-registered client credentials or mTLS, beyond the built-in dynamic client registration.

class MyAgent extends Agent { …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Interaktive Browser-Terminals in Sandboxes

Das Sandbox SDK unterstützt PTY-Passthrough, sodass Browser-Terminals per WebSocket über sandbox.terminal() mit Sandbox-Shells verbunden werden können, mit mehreren isolierten Terminals pro Sandbox und einem xterm.js-Addon mit automatischer Wiederverbindung.

The Sandbox SDK ↗︎ now supports PTY (pseudo-terminal) passthrough, enabling browser-based terminal UIs to connect to sandbox shells via WebSocket.

sandbox.terminal(request)

The new terminal() method proxies a WebSocket upgrade to the container's PTY endpoint, with output buffering for replay on reconnect.

// Worker: proxy WebSocket to container terminal
return sandbox.terminal(request, { cols: 80, rows: 24 });
// Worker: proxy WebSocket to container terminal
return sandbox.terminal(request, { cols: 80, rows: 24 });

Multiple terminals per sandbox

Each session can have its own terminal with an isolated working directory and environment, so users can run separate shells side-by-side in the same container.

// Multiple isolated terminals in the same sandbox
const dev = await sandbox.getSession("dev");
return dev.terminal(request);
// Multiple isolated terminals in the same sandbox
const dev = await sandbox.getSession("dev");
return dev.terminal(request);

xterm.js addon

The new @cloudflare/sandbox/xterm export provides a SandboxAddon for xterm.js ↗︎ with automatic reconnection (exponential backoff + jitter), buffered output replay, and resize forwarding.

import { SandboxAddon } from "@cloudflare/sandbox/xterm";

const addon = new SandboxAddon({ …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search: Feinere Kontrolle über die Indexierung

In AI Search lassen sich einzelne Dateien ohne vollständigen Sync neu indexieren, und der Crawler kann auf eine bestimmte Sitemap-URL beschränkt werden statt auf alle Sitemaps aus der robots.txt.

Get your content updates into AI Search faster and avoid a full rescan when you do not need it.

Reindex individual files without a full sync

Updated a file or need to retry one that errored? When you know exactly which file changed, you can now reindex it directly instead of rescanning your entire data source.

Go to Overview > Indexed Items and select the sync icon next to any file to reindex it immediately.

Sync individual files from Indexed Items

Crawl only the sitemap you need

By default, AI Search crawls all sitemaps listed in your robots.txt, up to the maximum files per index limit. If your site has multiple sitemaps but you only want to index a specific set, you can now specify a single sitemap URL to limit what the crawler visits. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 SQL unterstützt approximative Aggregationsfunktionen

R2 SQL bietet fünf neue approximative Aggregationsfunktionen (APPROX_PERCENTILE_CONT, APPROX_PERCENTILE_CONT_WITH_WEIGHT, APPROX_MEDIAN, APPROX_DISTINCT, APPROX_TOP_K), die bei großen Datensätzen etwas Genauigkeit gegen mehr Geschwindigkeit tauschen.

R2 SQL now supports five approximate aggregation functions for fast analysis of large datasets. These functions trade minor precision for improved performance on high-cardinality data.

New functions

  • APPROX_PERCENTILE_CONT(column, percentile) — Returns the approximate value at a given percentile (0.0 to 1.0). Works on integer and decimal columns.
  • APPROX_PERCENTILE_CONT_WITH_WEIGHT(column, weight, percentile) — Weighted percentile calculation where each row contributes proportionally to its weight column value.
  • APPROX_MEDIAN(column) — Returns the approximate median. Equivalent to APPROX_PERCENTILE_CONT(column, 0.5).
  • APPROX_DISTINCT(column) — Returns the approximate number of distinct values. Works on any column type.
  • APPROX_TOP_K(column, k) — Returns the k most frequent values with their counts as a JSON array.

All functions support WHERE filters. All except APPROX_TOP_K support GROUP BY.

Examples

-- Percentile analysis on revenue data
SELECT approx_percentile_cont(total_amount, 0.25),
       approx_percentile_cont(total_amount, 0.5),
       approx_percentile_cont(total_amount, 0.75)
FROM my_namespace.sales_data
-- Median per department
SELECT department, approx_median(total_amount)
FROM my_namespace.sales_data
GROUP BY department
-- Approximate distinct customers by region
SELECT region, approx_distinct(customer_id)
FROM my_namespace.sales_data
GROUP BY region
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

AI Crawl Control: erweiterte Analysefunktionen

AI Crawl Control bietet neue Ansichten für Pfadmuster, Verweise, Datenübertragung und Bildexporte in den Metriken, um KI-Traffic besser zu analysieren.

AI Crawl Control metrics have been enhanced with new views, improved filtering, and better data visualization.

AI Crawl Control path patterns

Path pattern grouping

  • In the Metrics tab > Most popular paths table, use the new Patterns tab that groups requests by URI pattern (/blog/*, /api/v1/*, /docs/*) to identify which site areas crawlers target most. Refer to the screenshot above.

Enhanced referral analytics

  • Destination patterns show which site areas receive AI-driven referral traffic.
  • In the Metrics tab, a new Referrals over time chart shows trends by operator or source.

Data transfer metrics

  • In the Metrics tab > Allowed requests over time chart, toggle Bytes to show bandwidth consumption.
  • In the Crawlers tab, a new Bytes Transferred column shows bandwidth per crawler.

Image exports

  • Export charts and tables as images for reports and presentations.

Learn more about analyzing AI traffic.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Log Explorer: Tabs und Pivot-Funktionen

Der Log Explorer unterstützt nun mehrere parallele Abfragen in Tabs, schnelles Filtern aus Ergebnissen und das Öffnen neuer Abfragen per Cmd-Klick, wobei der Fortschritt in jedem Tab erhalten bleibt.

Log Explorer now supports multiple concurrent queries with the new Tabs feature. Work with multiple queries simultaneously and pivot between datasets to investigate malicious activity more effectively.

Key capabilities

  • Multiple tabs: Open and switch between multiple query tabs to compare results across different datasets.
  • Quick filtering: Select the filter button from query results to add a value as a filter to your current query.
  • Pivot to new tab: Use Cmd + click on the filter button to start a new query tab with that filter applied.
  • Preserved progress: Your query progress is preserved on each tab if you navigate away and return.

For more information, refer to the Log Explorer documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neues Workers-Observability-Dashboard mit Visualisierungen und Export

Das Workers-Observability-Dashboard erlaubt nun Diagramme, Export von Logs und Traces als JSON oder CSV, teilbare Links zu Events und Traces, anpassbare Tabellenspalten, aufklappbare Eventdetails und Tastenkürzel.

The Workers Observability dashboard ↗︎ has some major updates to make it easier to debug your application's issues and share findings with your team.

Workers Observability dashboard showing events view with event details and share options

You can now:

  • Create visualizations — Build charts from your Worker data directly in a Worker's Observability tab
  • Export data as JSON or CSV — Download logs and traces for offline analysis or to share with teammates
  • Share events and traces — Generate direct URLs to specific events, invocations, and traces that open standalone pages with full context
  • Customize table columns — Improved field picker to add, remove, and reorder columns in the events table
  • Expandable event details — Expand events inline to view full details without leaving the table
  • Keyboard shortcuts — Navigate the dashboard with hotkey support

Workers Observability dashboard showing a P99 CPU time visualization grouped by outcome …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Cloudflare Queues jetzt im Workers Free Plan verfügbar

Cloudflare Queues ist nun im Free Plan enthalten, mit bis zu 10.000 Queues und 10.000 Operationen pro Tag, allen bestehenden Funktionen und einer maximalen Aufbewahrung von 24 Stunden statt 14 Tagen.

Cloudflare Queues is now part of the Workers free plan, offering guaranteed message delivery across up to 10,000 queues to either Cloudflare Workers or HTTP pull consumers. Every Cloudflare account now includes 10,000 operations per day across reads, writes, and deletes. For more details on how each operation is defined, refer to Queues pricing ↗︎.

All features of the existing Queues functionality are available on the free plan, including unlimited event subscriptions. Note that the maximum retention period on the free tier, however, is 24 hours rather than 14 days.

If you are new to Cloudflare Queues, follow this guide ↗︎ or try one of our tutorials to get started.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workflows im Cloudflare-Dashboard visualisieren

Cloudflare Workflows erzeugt aus dem Code automatisch visuelle Diagramme mit Schritten, Schleifen und Verzweigungen, die in der Beta für alle JavaScript- und TypeScript-Workflows im Dashboard verfügbar sind.

Cloudflare Workflows now automatically generates visual diagrams from your code

Your Workflow is parsed to provide a visual map of the Workflow structure, allowing you to:

  • Understand how steps connect and execute
  • Visualize loops and nested logic
  • Follow branching paths for conditional logic

Example diagram

You can collapse loops and nested logic to see the high-level flow, or expand them to see every step.

Workflow diagrams are available in beta for all JavaScript and TypeScript Workflows. Find your Workflows in the Cloudflare dashboard ↗︎ to see their diagrams.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

AI Crawl Control: Neue Referenzdokumentation

Neue Referenzdokumentation für AI Crawl Control ist verfügbar, darunter GraphQL-API-Referenz, Bot-Referenz und Worker-Vorlagen zur Monetarisierung von Crawler-Zugriffen.

New reference documentation is now available for AI Crawl Control:

  • GraphQL API reference — Query examples for crawler requests, top paths, referral traffic, and data transfer. Includes key filters for detection IDs, user agents, and referrer domains.
  • Bot reference — Detection IDs and user agents for major AI crawlers from OpenAI, Anthropic, Google, Meta, and others.
  • Worker templates — Deploy the x402 Payment-Gated Proxy to monetize crawler access or charge bots while letting humans through free.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.3.7: Workflows-Integration, synchroner State, scheduleEvery()

Das Agents SDK 0.3.7 integriert Cloudflare Workflows über die neue Klasse AgentWorkflow, bringt synchrones State-Management und neue Scheduling-Funktionen wie scheduleEvery().

The latest release of the Agents SDK ↗︎ brings first-class support for Cloudflare Workflows, synchronous state management, and new scheduling capabilities.

Cloudflare Workflows integration

Agents excel at real-time communication and state management. Workflows excel at durable execution. Together, they enable powerful patterns where Agents handle WebSocket connections while Workflows handle long-running tasks, retries, and human-in-the-loop flows.

Use the new AgentWorkflow class to define workflows with typed access to your Agent:

import { AgentWorkflow } from "agents/workflows";

export class ProcessingWorkflow extends AgentWorkflow {
	async run(event, step) {
		// Call Agent methods via RPC
		await this.agent.updateStatus(event.payload.taskId, "processing");

		// Non-durable: progress reporting to clients
		await this.reportProgress({ step: "process", percent: 0.5 });
		this.broadcastToClients({ type: "update", taskId: event.payload.taskId });

		// Durable via step: idempotent, won't repeat on retry
		await step.mergeAgentState({ taskProgress: 0.5 });

		const result = await step.do("process", async () => {
			return processData(event.payload.data);
		});

		await step.reportComplete(result);
		return result;
	}
}
import { AgentWorkflow } from "agents/workflows"; …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 Local Uploads jetzt in der Open Beta

R2 Local Uploads ist in der Open Beta verfügbar und schreibt Objektdaten nahe am Client, um bei Uploads aus anderen Regionen die Time to Last Byte um bis zu 75 % zu senken, wobei Objekte sofort und stark konsistent verfügbar bleiben.

Local Uploads is now available in open beta. Enable it on your R2 bucket to improve upload performance when clients upload data from a different region than your bucket. With Local Uploads enabled, object data is written to storage infrastructure near the client, then asynchronously replicated to your bucket. The object is immediately accessible and remains strongly consistent throughout. Refer to How R2 works for details on how data is written to your bucket.

In our tests, we observed up to 75% reduction in Time to Last Byte (TTLB) for upload requests when Local Uploads is enabled.

Local Uploads latency comparison showing p50 TTLB dropping from around 2 seconds to 500ms after enabling Local Uploads

This feature is ideal when:

  • Your users are globally distributed
  • Upload performance and reliability is critical to your application
  • You want to optimize write performance without changing your bucket's primary location

To enable Local Uploads on your bucket, find Local Uploads in your bucket settings in the Cloudflare Dashboard ↗︎, or run:

npx wrangler r2 bucket local-uploads enable <BUCKET_NAME> …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Threat-Actor-Aliasse in Threat Events

Threat Events zeigen jetzt im Dashboard und über die API das Feld „Also known as“ mit gängigen Aliasnamen für verfolgte Gruppen.

Identifying threat actors can be challenging, because naming conventions often vary across the security industry. To simplify your research, Cloudflare Threat Events now include an Also known as field, providing a list of common aliases and industry-standard names for the groups we track.

This new field is available in both the Cloudflare dashboard and via the API. In the dashboard, you can view these aliases by expanding the event details side panel (under the Attacker field) or by adding it as a column in your configurable table view.

Key benefits

  • Easily map Cloudflare-tracked actors to the naming conventions used by other vendors without manual cross-referencing.
  • Quickly identify if a detected threat actor matches a group your team is already monitoring via other intelligence feeds.

For more information on how to access this data, refer to the Threat Events API documentation ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: Verbesserte Monitoring-Seite mit Suche

Die Monitoring-Seite der Email Security bietet nun Stacked-Bar-Charts, bessere Kontraste, Suche in mehreren Widgets, klarere Statusanzeigen sowie neue Detailansichten etwa zu Dispositions pro Monat und Impersonations für alle Pakete.

We have updated the Monitoring page to provide a more streamlined and insightful experience for administrators, improving both data visualization and dashboard accessibility.

  • Enhanced Visual Layout: Optimized contrast and the introduction of stacked bar charts for clearer data visualization and trend analysis. visual-example
  • Improved Accessibility & Usability:
    • Widget Search: Added search functionality to multiple widgets, including Policies, Submitters, and Impersonation.
    • Actionable UI: All available actions are now accessible via dedicated buttons.
    • State Indicators: Improved UI states to clearly communicate loading, empty datasets, and error conditions. buttons-example
  • Granular Data Breakdowns: New views for dispositions by month, malicious email details, link actions, and impersonations. monthly-example

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Release mit neuen Erkennungen für CVE-2025-64459 und CVE-2025-24893

Neue WAF-Regeln blockieren Angriffe auf Django (SQL-Injection, CVE-2025-64459) und XWiki (Remote Code Execution, CVE-2025-24893).

This week’s release introduces new detections for CVE-2025-64459 and CVE-2025-24893.

Key Findings

  • CVE-2025-64459: Django versions prior to 5.1.14, 5.2.8, and 4.2.26 are vulnerable to SQL injection via crafted dictionaries passed to QuerySet methods and the Q() class.
  • CVE-2025-24893: XWiki allows unauthenticated remote code execution through crafted requests to the SolrSearch endpoint, affecting the entire installation.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...30698ff3

N/A

XWiki - Remote Code Execution - CVE:CVE-2025-24893 2

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...da8ba7e6

N/A

Django SQLI - CVE:CVE-2025-64459

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...8d667511

N/A

NoSQL, MongoDB - SQLi - Comparison - 2

Block

Block

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

BGP über GRE- und IPsec-Tunnel (Beta)

Magic-WAN- und Magic-Transit-Kunden können im Dashboard BGP-Peering über IPsec- und GRE-Tunnel-On-Ramps (Beta) einrichten, um eBGP-Sitzungen mit MD5-Authentifizierung aufzubauen und Routen dynamisch mit der Magic-Routingtabelle auszutauschen.

Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using IPsec and GRE tunnel on-ramps (beta).

Using BGP peering allows customers to:

  • Automate the process of adding or removing networks and subnets.
  • Take advantage of failure detection and session recovery features.

With this functionality, customers can:

  • Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via IPsec and GRE tunnel on-ramps.
  • Secure the session by MD5 authentication to prevent misconfigurations.
  • Exchange routes dynamically between their devices and their Magic routing table.

For configuration details, refer to:

Originalquelle(öffnet in neuem Tab)Problem melden