Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

SQL-Dateien standardmäßig als Module importierbar

Die Dateiendung .sql ist in Wrangler und im Cloudflare Vite plugin nun automatisch als importierbares Modul konfiguriert und wird als JavaScript-String importiert, sodass für Drizzle keine eigenen Regeln mehr nötig sind.

The .sql file extension is now automatically configured to be importable in your Worker code when using Wrangler or the Cloudflare Vite plugin. This is particular useful for importing migrations in Durable Objects and means you no longer need to configure custom rules when using Drizzle ↗︎.

SQL files are imported as JavaScript strings:

// `example` will be a JavaScript string
import example from "./example.sql";

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Verbesserungen gegen SQL-Injection

Zwei überarbeitete WAF-Regeln zur SQL-Injection-Erkennung wurden in die regulären Regeln überführt und blockieren nun aktiv.

This week's release focuses on improvements to existing detections to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against SQL injection.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...68d90c8f

N/A

SQLi - Comment - Beta

Log

Block

This rule is merged into the original rule "SQLi - Comment" (ID: ...6d8d8fe4)

Cloudflare Managed Ruleset

...faa045cf

N/A

SQLi - Comparison - Beta

Log

Block

This rule is merged into the original rule "SQLi - Comparison" (ID: ...e7907480)

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Neue Funktionen für Arrays und Maps in Rulesets

Cloudflare Rulesets bietet jetzt die Funktionen split(), join(), has_key() und has_value() für erweiterte Ausdruckslogik mit Arrays und Maps, z. B. zur länderspezifischen Blockierung.

New functions for array and map operations

Cloudflare Rulesets now include new functions that enable advanced expression logic for evaluating arrays and maps. These functions allow you to build rules that match against lists of values in request or response headers, enabling use cases like country-based blocking using custom headers.


New functions

Function

Description

split(source, delimiter)

Splits a string into an array of strings using the specified delimiter.

join(array, delimiter)

Joins an array of strings into a single string using the specified delimiter.

has_key(map, key)

Returns true if the specified key exists in the map.

has_value(map, value)

Returns true if the specified value exists in the map.


Example use cases

Check if a country code exists in a header list:

has_value(split(http.response.headers["x-allow-country"][0], ","), ip.src.country)

Check if a specific header key exists:

has_key(http.request.headers, "x-custom-header")

Join array values for logging or comparison:

join(http.request.headers.names, ", ")

For more information, refer to the Functions reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Cloudflare TypeScript SDK v6.0.0-beta.1 verfügbar

Das Cloudflare TypeScript SDK v6.0.0-beta.1 enthält zahlreiche Breaking Changes aufgrund geänderter OpenAPI-Definitionen und Codegen-Updates; Parameteranforderungen wurden angepasst und einige API-Schemata entfernt oder umbenannt.

Disclaimer: Please note that v6.0.0-beta.1 is in Beta and we are still testing it for stability.

Full Changelog: v5.2.0...v6.0.0-beta.1 ↗︎

In this release, you'll see a large number of breaking changes. This is primarily due to a change in OpenAPI definitions, which our libraries are based off of, and codegen updates that we rely on to read those OpenAPI definitions and produce our SDK libraries. As the codegen is always evolving and improving, so are our code bases.

Some breaking changes were introduced due to bug fixes, also listed below.

Please ensure you read through the list of changes below before moving to this version - this will help you understand any down or upstream issues it may cause to your environments.


Breaking Changes

Addressing - Parameter Requirements Changed

  • BGPPrefixCreateParams.cidr: optional → required
  • PrefixCreateParams.asn: number | null → number
  • PrefixCreateParams.loa_document_id: required → optional
  • ServiceBindingCreateParams.cidr: optional → required
  • ServiceBindingCreateParams.service_id: optional → required

API Gateway

  • ConfigurationUpdateResponse removed
  • PublicSchema → OldPublicSchema
  • SchemaUpload → UserSchemaCreateResponse …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform Provider v5.16.0 verfügbar

Der Terraform Provider v5.16.0 enthält Bugfixes, Stabilisierungen weiterer Ressourcen und neue Features wie die Unterstützung von „waf_challenge“ als Fehlerseitentyp; ein Migrationswerkzeug von v4 zu v5 ist für Ende März 2026 geplant.

In January 2025, we announced the launch of the new Terraform v5 Provider. We greatly appreciate the proactive engagement and valuable feedback from the Cloudflare community following the v5 release. In response, we've established a consistent and rapid 2-3 week cadence ↗︎ for releasing targeted improvements, demonstrating our commitment to stability and reliability.

With the help of the community, we have a growing number of resources that we have marked as stable ↗︎, with that list continuing to grow with every release. The most used resources ↗︎ are on track to be stable by the end of March 2026, when we will also be releasing a new migration tool to you migrate from v4 to v5 with ease.

Thank you for continuing to raise issues. They make our provider stronger and help us build products that reflect your needs.

This release includes bug fixes, the stabilization of even more popular resources, and more.

Features

  • custom_pages: add "waf_challenge" as new supported error page type identifier in both resource and data source schemas
  • list: enhance CIDR validator to check for normalized CIDR notation requiring network address for IPv4 and IPv6 …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Bessere Sichtbarkeit bei HTTP/3-Abbruch

Cloudflare beendet abgebrochene HTTP/3-Anfragen jetzt sofort und protokolliert sie mit Statuscode 499, was genauere Analysen, klareres Debugging und eine reduzierte Origin-Last ermöglicht.

Enhanced HTTP/3 request cancellation visibility

Cloudflare now provides more accurate visibility into HTTP/3 client request cancellations, giving you better insight into real client behavior and reducing unnecessary load on your origins.

Previously, when an HTTP/3 client cancelled a request, the cancellation was not always actioned immediately. This meant requests could continue through the CDN — potentially all the way to your origin — even after the client had abandoned them. In these cases, logs would show the upstream response status (such as 200 or a timeout-related code) rather than reflecting the client cancellation.

Now, Cloudflare terminates cancelled HTTP/3 requests immediately and accurately logs them with a 499 status code.


Better observability for client behavior

When HTTP/3 clients cancel requests, Cloudflare now immediately reflects this in your logs with a 499 status code. This gives you:

  • More accurate traffic analysis: Understand exactly when and how often clients cancel requests.
  • Clearer debugging: Distinguish between true errors and intentional client cancellations.
  • Better availability metrics: Separate client-initiated cancellations from server-side issues.

Reduced origin load

Cloudflare now terminates cancelled requests faster, which means: …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Neue Navigation für Network Services im Dashboard

Das Menü „Network Services“ ist nach Lösungen statt Produktnamen gegliedert, mit neuer Overview-Seite, Konfiguration unter Routes und Connectors sowie Analysen unter Insights, während Konfigurationen und Funktionen unverändert bleiben.

The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.

Your existing configurations will remain the same, and you will have access to all of the same features and functionality.

The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit ↗︎, Magic WAN ↗︎, and Magic Firewall ↗︎.

Summary of changes:

  • A new Overview page provides access to the most common tasks across Magic Transit and Magic WAN.
  • Product names have been removed from top-level navigation.
  • Magic Transit and Magic WAN configuration is now organized under Routes and Connectors. For example, you will find IP Prefixes under Routes, and your GRE/IPsec Tunnels under Connectors.
  • Magic Firewall policies are now called Firewall Policies.
  • Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as Appliances and Appliance profiles. They can be found under Connectors > Appliances.
  • Network analytics, network health, and real-time analytics are now available under Insights. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

CrowdStrike-Gerätescores im User Risk Scoring

Das User Risk Scoring bietet für Organisationen mit CrowdStrike-Integration zwei neue Verhaltensweisen, die den Risikoscore eines Nutzers automatisch erhöhen, wenn das Gerät von CrowdStrike einen niedrigen oder mittleren ZTA-Score meldet.

Cloudflare One has expanded its [User Risk Scoring] (/cloudflare-one/insights/risk-score/) capabilities by introducing two new behaviors for organizations using the [CrowdStrike integration] (/cloudflare-one/integrations/service-providers/crowdstrike/).

Administrators can now automatically escalate the risk score of a user if their device matches specific CrowdStrike Zero Trust Assessment (ZTA) score ranges. This allows for more granular security policies that respond dynamically to the health of the endpoint.

New risk behaviors The following risk scoring behaviors are now available:

  • CrowdStrike low device score: Automatically increases a user's risk score when the connected device reports a "Low" score from CrowdStrike.
  • CrowdStrike medium device score: Automatically increases a user's risk score when the connected device reports a "Medium" score from CrowdStrike.

These scores are derived from [CrowdStrike device posture attributes] (/cloudflare-one/integrations/service-providers/crowdstrike/#device-posture-attributes), including OS signals and sensor configurations.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP Connector per Ping auf LAN-IP prüfen

Ab Version 2025.10.186.0 antwortet der WARP Connector auf Datenverkehr an seine eigene LAN-IP, sodass sich die Erreichbarkeit direkt nach der Installation per ping prüfen lässt.

We have made it easier to validate connectivity when deploying WARP Connector as part of your software-defined private network.

You can now ping the WARP Connector host directly on its LAN IP address immediately after installation. This provides a fast, familiar way to confirm that the Connector is online and reachable within your network before testing access to downstream services.

Starting with version 2025.10.186.0, WARP Connector responds to traffic addressed to its own LAN IP, giving you immediate visibility into Connector reachability.

Learn more about deploying WARP Connector and building private network connectivity with Cloudflare One.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

FLUX.2 [klein] 4B jetzt auf Workers AI verfügbar

Workers AI bietet jetzt das von Black Forest Labs stammende, destillierte Modell FLUX.2 [klein] 4B mit fest eingestellten 4 Inferenzschritten, bis zu 4 Bildeingaben und Multipart-Form-Data-Eingaben für schnelle und günstige Bildgenerierung an.

We've partnered with Black Forest Labs (BFL) again to bring their optimized FLUX.2 [klein] 4B model to Workers AI! This distilled model offers faster generation and cost-effective pricing, while maintaining great output quality. With a fixed 4-step inference process, Klein 4B is ideal for rapid prototyping and real-time applications where speed matters.

Read the BFL blog ↗︎ to learn more about the model itself, or try it out yourself on our multi modal playground ↗︎.

Pricing documentation is available on the model page or pricing page.

Workers AI Platform specifics

The model hosted on Workers AI is optimized for speed with a fixed 4-step inference process and supports up to 4 image inputs. Since this is a distilled model, the steps parameter is fixed at 4 and cannot be adjusted. Like FLUX.2 [dev], this image model uses multipart form data inputs, even if you just have a prompt.

With the REST API, the multipart form data input looks like this:

curl --request POST \
  --url 'https://api.cloudflare.com/client/v4/accounts/{ACCOUNT}/ai/run/@cf/black-forest-labs/flux-2-klein-4b' \
  --header 'Authorization: Bearer {TOKEN}' \
  --header 'Content-Type: multipart/form-data' \
  --form 'prompt=a sunset at the alps' \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Verbesserungen gegen SQL-Injection

Zwei Beta-Regeln zur SQL-Injection-Erkennung wurden mit den regulären Regeln zusammengeführt und blockieren nun Angriffe.

This week's release focuses on improvements to existing detections to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against SQL Injection.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...ad7dad3e

N/A

SQLi - String Function - Beta

Log

Block

This rule is merged into the original rule "SQLi - String Function" (ID: ...d32b798c)

Cloudflare Managed Ruleset

...9e553ad3

N/A

SQLi - Sub Query - Beta

Log

Block

This rule is merged into the original rule "SQLi - Sub Query" (ID: ...743e66b1)

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

WARP Connector-Konnektivität per Ping prüfen

Sie können den WARP Connector jetzt direkt per Ping auf seiner LAN-IP-Adresse erreichen, um die Konnektivität nach der Installation schnell zu bestätigen; dies gilt ab Version 2025.10.186.0.

We have made it easier to validate connectivity when deploying WARP Connector as part of your software-defined private network.

You can now ping the WARP Connector host directly on its LAN IP address immediately after installation. This provides a fast, familiar way to confirm that the Connector is online and reachable within your network before testing access to downstream services.

Starting with version 2025.10.186.0, WARP Connector responds to traffic addressed to its own LAN IP, giving you immediate visibility into Connector reachability.

Learn more about deploying WARP Connector and building private network connectivity with Cloudflare One.

Originalquelle(öffnet in neuem Tab)Problem melden

Network Security von Cloudflare

Network Services-Navigation im Dashboard umstrukturiert

Die Navigation für Netzwerkdienste im Dashboard wurde neu organisiert, um Lösungen statt Produktnamen hervorzuheben; bestehende Konfigurationen bleiben unverändert.

The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.

Your existing configurations will remain the same, and you will have access to all of the same features and functionality.

The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit ↗︎, Magic WAN ↗︎, and Magic Firewall ↗︎.

Summary of changes:

  • A new Overview page provides access to the most common tasks across Magic Transit and Magic WAN.
  • Product names have been removed from top-level navigation.
  • Magic Transit and Magic WAN configuration is now organized under Routes and Connectors. For example, you will find IP Prefixes under Routes, and your GRE/IPsec Tunnels under Connectors.
  • Magic Firewall policies are now called Firewall Policies.
  • Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as Appliances and Appliance profiles. They can be found under Connectors > Appliances.
  • Network analytics, network health, and real-time analytics are now available under Insights. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

URL-Scanner unterstützt PDF-Berichte

Der Cloudflare URL Scanner bietet nun PDF-Downloads für Scan-Ergebnisse direkt im Dashboard an.

We have expanded the reporting capabilities of the Cloudflare URL Scanner. In addition to existing JSON and HAR exports, users can now generate and download a PDF report directly from the Cloudflare dashboard. This update streamlines how security analysts can share findings with stakeholders who may not have access to the Cloudflare dashboard or specialized tools to parse JSON and HAR files.

Key Benefits:

  • Consolidate scan results, including screenshots, security signatures, and metadata, into a single, portable document
  • Easily share professional-grade summaries with non-technical stakeholders or legal teams for faster incident response

What’s new:

  • PDF Export Button: A new download option is available in the URL Scanner results page within the Cloudflare dashboard
  • Unified Documentation: Access all scan details—from high-level summaries to specific security flags—in one offline-friendly file

To get started with the URL Scanner and explore our reporting capabilities, visit the URL Scanner API documentation ↗︎.


Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für Windows 2025.10.186.0 (GA)

Die GA-Version 2025.10.186.0 des WARP-Clients für Windows bringt unter anderem die Steuerung der WARP-Konnektivität aller Geräte per externem Signal (Emergency Disconnect) und einen neuen Device-Posture-Check für Antivirus.

A new GA release for the Windows WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features. New features include the ability to manage WARP client connectivity for all devices in your fleet using an external signal, and a new WARP client device posture check for Antivirus.

Changes and improvements

  • Added a new feature to manage WARP client connectivity for all devices using an external signal. This feature allows administrators to send a global signal from an on-premises HTTPS endpoint that force disconnects or reconnects all WARP clients in an account based on configuration set on the endpoint. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für macOS 2025.10.186.0 (GA)

Der macOS WARP client 2025.10.186.0 ist als GA-Release verfügbar, ermöglicht die Steuerung der WARP-Verbindung aller Geräte per externem Signal, behebt Local Domain Fallback ohne konfigurierten Fallback-Server und unterstützt im Proxy mode nun transparentes HTTP-Proxying.

A new GA release for the macOS WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features, including the ability to manage WARP client connectivity for all devices in your fleet using an external signal.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly.
  • Proxy mode now supports transparent HTTP proxying in addition to CONNECT-based proxying. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für Linux 2025.10.186.0 (GA)

Der Linux WARP client 2025.10.186.0 ist als GA-Release verfügbar, erlaubt die Steuerung der WARP-Verbindung per externem Signal und behebt Local Domain Fallback ohne konfigurierten Fallback-Server; zudem muss der öffentliche Schlüssel für Linux-Pakete, falls vor dem 12. September 2025 installiert, aktualisiert werden.

A new GA release for the Linux WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features, including the ability to manage WARP client connectivity for all devices in your fleet using an external signal.

WARP client version 2025.8.779.0 introduced an updated public key for Linux packages. The public key must be updated if it was installed before September 12, 2025 to ensure the repository remains functional after December 4, 2025. Instructions to make this update are available at pkg.cloudflareclient.com.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

wrangler types erzeugt Typen für alle Umgebungen

Der Befehl wrangler types generiert nun standardmäßig TypeScript-Typen für Bindings aller in der Wrangler-Konfiguration definierten Umgebungen, und das bisherige Verhalten lässt sich mit dem Flag --env erhalten.

The wrangler types command now generates TypeScript types for bindings from all environments defined in your Wrangler configuration file by default.

Previously, wrangler types only generated types for bindings in the top-level configuration (or a single environment when using the --env flag). This meant that if you had environment-specific bindings — for example, a KV namespace only in production or an R2 bucket only in staging — those bindings would be missing from your generated types, causing TypeScript errors when accessing them.

Now, running wrangler types collects bindings from all environments and includes them in the generated Env type. This ensures your types are complete regardless of which environment you deploy to.

Generating types for a specific environment

If you want the previous behavior of generating types for only a specific environment, you can use the --env flag:

wrangler types --env production

Learn more about generating types for your Worker in the Wrangler documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

wrangler types erzeugt Typen für alle Umgebungen

wrangler types generiert standardmäßig TypeScript-Typen für Bindings aus allen in der Wrangler-Konfiguration definierten Umgebungen, und mit --env lässt sich weiterhin nur eine einzelne Umgebung auswählen.

The wrangler types command now generates TypeScript types for bindings from all environments defined in your Wrangler configuration file by default.

Previously, wrangler types only generated types for bindings in the top-level configuration (or a single environment when using the --env flag). This meant that if you had environment-specific bindings — for example, a KV namespace only in production or an R2 bucket only in staging — those bindings would be missing from your generated types, causing TypeScript errors when accessing them.

Now, running wrangler types collects bindings from all environments and includes them in the generated Env type. This ensures your types are complete regardless of which environment you deploy to.

Generating types for a specific environment

If you want the previous behavior of generating types for only a specific environment, you can use the --env flag:

wrangler types --env production

Learn more about generating types for your Worker in the Wrangler documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

AI Crawl Control: Neue Rolle „Read Only“ verfügbar

Administratoren können jetzt die Rolle „AI Crawl Control Read Only“ zuweisen, um Benutzern schreibgeschützten Zugriff auf die AI-Crawl-Control-Funktionen auf Domain-Ebene zu gewähren.

Account administrators can now assign the AI Crawl Control Read Only role to provide read-only access to AI Crawl Control at the domain level.

Users with this role can view the Overview, Crawlers, Metrics, Robots.txt, and Settings tabs but cannot modify crawler actions or settings.

This role is specific for AI Crawl Control. You still require correct permissions to access other areas / features of the dashboard.

To assign, go to Manage Account > Members and add a policy with the AI Crawl Control Read Only role scoped to the desired domain.

Originalquelle(öffnet in neuem Tab)Problem melden