Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Authentifizierungs-Token mit wrangler auth token abrufen

Der neue Befehl wrangler auth token gibt das aktuell konfigurierte Authentifizierungs-Token bzw. die Zugangsdaten für andere Tools und Skripte aus, mit --json auch inklusive Token-Typ.

Wrangler now includes a new wrangler auth token command that retrieves your current authentication token or credentials for use with other tools and scripts.

wrangler auth token

The command returns whichever authentication method is currently configured, in priority order: API token from CLOUDFLARE_API_TOKEN, or OAuth token from wrangler login (automatically refreshed if expired).

Use the --json flag to get structured output including the token type:

wrangler auth token --json

The JSON output includes the authentication type:

// API token
{ "type": "api_token", "token": "..." }

// OAuth token
{ "type": "oauth", "token": "..." }

// API key/email (only available with --json)
{ "type": "api_key", "key": "...", "email": "..." }

API key/email credentials from CLOUDFLARE_API_KEY and CLOUDFLARE_EMAIL require the --json flag since this method uses two values instead of a single token.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Release mit Regelverbesserungen und neuen Erkennungen

WAF-Regeln für Confluence, PostgreSQL und SQLi wurden verbessert; drei neue generische Regeln zur Befehlserkennung wurden hinzugefügt.

This week's release focuses on improvements to existing detections to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...be5ec20c

N/A

Atlassian Confluence - Code Injection - CVE:CVE-2021-26084 - Beta

Log

Block

This rule is merged into the original rule "Atlassian Confluence - Code Injection - CVE:CVE-2021-26084" (ID: ...69e0b97a)

Cloudflare Managed Ruleset

...0d9206e3

N/A

PostgreSQL - SQLi - Copy - Beta

Log

Block

This rule is merged into the original rule "PostgreSQL - SQLi - COPY" (ID: ...e7265a4e)

Cloudflare Managed Ruleset

...0cd00ba7

N/A

Generic Rules - Command Execution - Body

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...cd679ad4

N/A

Generic Rules - Command Execution - Header

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...fd181fb3

N/A

Generic Rules - Command Execution - URI

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...7a95bc3a

N/A

SQLi - Tautology - URI - Beta

Log

Block

This rule is merged into the original rule "SQLi - Tautology - URI" (ID: ...b3de2e0a)

Cloudflare Managed Ruleset

...432ac90d

N/A

SQLi - WaitFor Function - Beta

Log

Block …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

AI Crawl Control: Neuer Überblick-Tab

Der neue „Überblick“-Tab ist die Standardansicht in AI Crawl Control und bietet eine Zusammenfassung, Gruppierung nach Betreibern und Filteroptionen.

The Overview tab is now the default view in AI Crawl Control. The previous default view with controls for individual AI crawlers is available in the Crawlers tab.

What's new

  • Executive summary — Monitor total requests, volume change, most common status code, most popular path, and high-volume activity
  • Operator grouping — Track crawlers by their operating companies (OpenAI, Microsoft, Google, ByteDance, Anthropic, Meta)
  • Customizable filters — Filter your snapshot by date range, crawler, operator, hostname, or path

AI Crawl Control Overview tab showing executive summary, metrics, and crawler groups

Get started

  1. Log in to the Cloudflare dashboard and select your account and domain.
  2. Go to AI Crawl Control, where the Overview tab opens by default with your activity snapshot.
  3. Use filters to customize your view by date range, crawler, operator, hostname, or path.
  4. Navigate to the Crawlers tab to manage controls for individual crawlers.

Learn more about analyzing AI traffic and managing AI crawlers.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Genauere Cache-Klassifizierung in Analytics

Die Cache-Klassifizierung in der Zone-Übersicht wurde korrigiert, sodass nur echte Cache-Treffer als „gecacht“ zählen und die Cache-Quoten nun die tatsächliche Leistung widerspiegeln.

The cached/uncached classification logic used in Zone Overview analytics has been updated to improve accuracy.

Previously, requests were classified as "cached" based on an overly broad condition that included blocked 403 responses, Snippets requests, and other non-cache request types. This caused inflated cache hit ratios — in some cases showing near-100% cached — and affected approximately 15% of requests classified as cached in rollups.

The condition has been removed from the Zone Overview page. Cached/uncached classification now aligns with the heuristics used in HTTP Analytics, so only requests genuinely served from cache are counted as cached.

What changed:

  • Zone Overview — Cache ratios now reflect actual cache performance.
  • HTTP Analytics — No change. HTTP Analytics already used the correct classification logic.
  • Historical data — This fix applies to new requests only. Previously logged data is not retroactively updated.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Shadow IT: SaaS-Analysen auf Domain-Ebene

Die Shadow IT analytics zeigen Datentransfer-Metriken nun auf Domain-Ebene statt nur auf Anwendungsebene und lassen sich mit allen Dashboard-Filtern wie Nutzer, Anwendung oder Inhaltskategorie filtern.

Zero Trust has again upgraded its Shadow IT analytics, providing you with unprecedented visibility into your organizations use of SaaS tools. With this dashboard, you can review who is using an application and volumes of data transfer to the application.

With this update, you can review data transfer metrics at the domain level, rather than just the application level, providing more granular insight into your data transfer patterns.

New Domain Level Metrics

These metrics can be filtered by all available filters on the dashboard, including user, application, or content category.

Both the analytics and policies are accessible in the Cloudflare Zero Trust dashboard ↗︎, empowering organizations with better visibility and control.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Neue Duplizieren-Aktion für Cloudflare-One-Ressourcen

Access Applications, Access Policies und Gateway Policies lassen sich im Dashboard über das Überlaufmenü (⋮) mit einem Klick auf Duplicate duplizieren, weitere Ressourcen sollen im Laufe von 2026 folgen.

You can now duplicate specific Cloudflare One resources with a single click from the dashboard.

Initially supported resources:

  • Access Applications
  • Access Policies
  • Gateway Policies

To try this out, simply click on the overflow menu (⋮) from the resource table and click Duplicate. We will continue to add the Duplicate action for resources throughout 2026.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

ctx.exports in @cloudflare/vitest-pool-workers unterstützt

@cloudflare/vitest-pool-workers unterstützt jetzt die ctx.exports API, sodass in Tests über createExecutionContext() oder den Import aus cloudflare:workers auf die Top-Level-Exports des Workers zugegriffen werden kann.

The @cloudflare/vitest-pool-workers package now supports the ctx.exports API, allowing you to access your Worker's top-level exports during tests.

You can access ctx.exports in unit tests by calling createExecutionContext():

import { createExecutionContext } from "cloudflare:test";
import { it, expect } from "vitest";

it("can access ctx.exports", async () => {
  const ctx = createExecutionContext();
  const result = await ctx.exports.MyEntryPoint.myMethod();
  expect(result).toBe("expected value");
});

Alternatively, you can import exports directly from cloudflare:workers:

import { exports } from "cloudflare:workers";
import { it, expect } from "vitest";

it("can access imported exports", async () => {
  const result = await exports.MyEntryPoint.myMethod();
  expect(result).toBe("expected value");
});

See the context-exports fixture ↗︎ for a complete example.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Automatische Framework-Konfiguration für Cloudflare mit Wrangler

Ab Wrangler 4.55 konfiguriert und deployt npx wrangler deploy --x-autoconfig unterstützte Web-Frameworks wie Next.js oder Astro im experimentellen Modus automatisch, und npx wrangler setup konfiguriert sie ohne Deployment.

Wrangler now supports automatic configuration for popular web frameworks in experimental mode, making it even easier to deploy to Cloudflare Workers.

Previously, if you wanted to deploy an application using a popular web framework like Next.js or Astro, you had to follow tutorials to set up your application for deployment to Cloudflare Workers. This usually involved creating a Wrangler file, installing adapters, or changing configuration options.

Now wrangler deploy does this for you. Starting with Wrangler 4.55, you can use npx wrangler deploy --x-autoconfig in the directory of any web application using one of the supported frameworks. Wrangler will then proceed to configure and deploy it to your Cloudflare account.

You can also configure your application without deploying it by using the new npx wrangler setup command. This enables you to easily review what changes we are making so your application is ready for Cloudflare Workers.

The following application frameworks are supported starting today:

  • Next.js
  • Astro
  • Nuxt
  • TanStack Start
  • SolidStart
  • React Router
  • SvelteKit
  • Docusaurus
  • Qwik
  • Analog

Automatic configuration also supports static sites by detecting the assets directory and build command. From a single index.html file to the output of a generator like Jekyll or Hugo, you can just run npx wrangler deploy --x-autoconfig to upload to Cloudflare. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neuer Best-Practices-Leitfaden für Durable Objects

Ein neuer Leitfaden „Rules of Durable Objects“ beschreibt Best Practices zu Design, Speicher, Nebenläufigkeit und Anti-Patterns, und die Testdokumentation wurde um moderne Muster mit @cloudflare/vitest-pool-workers aktualisiert.

A new Rules of Durable Objects guide is now available, providing opinionated best practices for building effective Durable Objects applications. This guide covers design patterns, storage strategies, concurrency, and common anti-patterns to avoid.

Key guidance includes:

  • Design around your "atom" of coordination — Create one Durable Object per logical unit (chat room, game session, user) instead of a global singleton that becomes a bottleneck.
  • Use SQLite storage with RPC methods — SQLite-backed Durable Objects with typed RPC methods provide the best developer experience and performance.
  • Understand input and output gates — Learn how Cloudflare's runtime prevents data races by default, how write coalescing works, and when to use blockConcurrencyWhile().
  • Leverage Hibernatable WebSockets — Reduce costs for real-time applications by allowing Durable Objects to sleep while maintaining WebSocket connections.

The testing documentation has also been updated with modern patterns using @cloudflare/vitest-pool-workers, including examples for testing SQLite storage, alarms, and direct instance access:

test/counter.test.jsjs

import { env, runDurableObjectAlarm } from "cloudflare:test";
import { it, expect } from "vitest"; …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 SQL unterstützt Aggregationen und Schema-Erkennung

R2 SQL unterstützt nun Aggregationsfunktionen, GROUP BY und HAVING sowie die Befehle SHOW DATABASES, SHOW TABLES und DESCRIBE zur Erkundung des Datenkatalogs.

R2 SQL now supports aggregation functions, GROUP BY, HAVING, along with schema discovery commands to make it easy to explore your data catalog.

Aggregation Functions

You can now perform aggregations on Apache Iceberg tables in R2 Data Catalog using standard SQL functions including COUNT(*), SUM(), AVG(), MIN(), and MAX(). Combine these with GROUP BY to analyze data across dimensions, and use HAVING to filter aggregated results.

-- Calculate average transaction amounts by department
SELECT department, COUNT(*), AVG(total_amount)
FROM my_namespace.sales_data
WHERE region = 'North'
GROUP BY department
HAVING COUNT(*) > 50
ORDER BY AVG(total_amount) DESC
-- Find high-value departments
SELECT department, SUM(total_amount)
FROM my_namespace.sales_data
GROUP BY department
HAVING SUM(total_amount) > 50000

Schema Discovery

New metadata commands make it easy to explore your data catalog and understand table structures:

  • SHOW DATABASES or SHOW NAMESPACES - List all available namespaces
  • SHOW TABLES IN namespace_name - List tables within a namespace
  • DESCRIBE namespace_name.table_name - View table schema and column types
❯ npx wrangler r2 sql query "{ACCOUNT_ID}_{BUCKET_NAME}" "DESCRIBE default.sales_data;"

 ⛅️ wrangler 4.54.0
───────────────────────────────────────────── …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Abrechnung für SQLite-Speicher bei Durable Objects

Die Speicherabrechnung für SQLite-basierte Durable Objects soll im Januar 2026 aktiviert werden (Zieldatum frühestens 7. Januar 2026), wobei nur Nutzer des Workers Paid Plans oberhalb der Inklusivgrenzen zahlen.

Storage billing for SQLite-backed Durable Objects will be enabled in January 2026, with a target date of January 7, 2026 (no earlier).

To view your SQLite storage usage, go to the Durable Objects page

Go to Durable Objects ↗

If you do not want to incur costs, please take action such as optimizing queries or deleting unnecessary stored data in order to reduce your SQLite storage usage ahead of the January 7th target. Only usage on and after the billing target date will incur charges.

Developers on the Workers Paid plan with Durable Object's SQLite storage usage beyond included limits will incur charges according to SQLite storage pricing announced in September 2024 with the public beta ↗︎. Developers on the Workers Free plan will not be charged.

Compute billing for SQLite-backed Durable Objects has been enabled since the initial public beta. SQLite-backed Durable Objects currently incur charges for requests and duration, and no changes are being made to compute billing. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Notfall-WAF-Release für CVE-2025-55183 und CVE-2025-55184

Neue WAF-Regeln blockieren Server-Funktionslecks und DoS-Angriffe auf React gemäß CVE-2025-55183 und CVE-2025-55184.

This emergency release introduces rules for CVE-2025-55183 and CVE-2025-55184, targeting server-side function exposure and resource-exhaustion patterns, respectively.

Key Findings

Added coverage for Leaking Server Functions (CVE-2025-55183) and React Function DoS detection (CVE-2025-55184).

Impact

These updates strengthen protection for server-function abuse techniques (CVE-2025-55183, CVE-2025-55184) that may expose internal logic or disrupt application availability.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...fefb4e9b

N/A

React - Leaking Server Functions - CVE:CVE-2025-55183

N/A

Block

This was labeled as Generic - Server Function Source Code Exposure.

Cloudflare Free Ruleset

...251e86aa

N/A

React - Leaking Server Functions - CVE:CVE-2025-55183

N/A

Block

This was labeled as Generic - Server Function Source Code Exposure.

Cloudflare Managed Ruleset

...102ec699

N/A

React - DoS - CVE:CVE-2025-55184

N/A

Disabled

This was labeled as Generic – Server Function Resource Exhaustion.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Logpush: SentinelOne als Ziel verfügbar

Cloudflare Logpush unterstützt jetzt SentinelOne als natives Ziel, konfigurierbar über die Logpush-Benutzeroberfläche oder die API.

Cloudflare Logpush now supports SentinelOne as a native destination.

Logs from Cloudflare can be sent to SentinelOne AI SIEM ↗︎ via Logpush. The destination can be configured through the Logpush UI in the Cloudflare dashboard or by using the Logpush API.

For more information, refer to the Destination Configuration documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Notfall-WAF-Release mit erweiterter React-Erkennung

Die WAF-Regel für React RCE CVE-2025-55182 wurde verbessert und zwei neue generische Regeln für Server-Funktionslecks und Ressourcenerschöpfung hinzugefügt.

This additional week's emergency release introduces improvements to our existing rule for React – Remote Code Execution – CVE-2025-55182 - 2, along with two new generic detections covering server-side function exposure and resource-exhaustion patterns.

Key Findings

Enhanced detection logic for React – RCE – CVE-2025-55182, added Generic – Server Function Source Code Exposure, and added Generic – Server Function Resource Exhaustion.

Impact

These updates strengthen protection against React RCE exploitation attempts and broaden coverage for common server-function abuse techniques that may expose internal logic or disrupt application availability.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...15fce168

N/A

React - Remote Code Execution - CVE:CVE-2025-55182 - 2

N/A

Block

This is an improved detection.

Cloudflare Free Ruleset

...74746aff

N/A

React - Remote Code Execution - CVE:CVE-2025-55182 - 2

N/A

Block

This is an improved detection.

Cloudflare Managed Ruleset

...fefb4e9b

N/A

Generic - Server Function Source Code Exposure

N/A

Block

This is a new detection.

Cloudflare Free Ruleset

...251e86aa

N/A

Generic - Server Function Source Code Exposure

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...102ec699

N/A

Generic - Server Function Resource Exhaustion

N/A

Disabled

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Pay Per Crawl: Discovery-API und mehr (Private Beta)

Pay Per Crawl erweitert die Private Beta um eine Discovery-API für Crawler, individuelle Preismodelle und erweiterte Konfigurationsoptionen.

Pay Per Crawl is introducing enhancements for both AI crawler operators and site owners, focusing on programmatic discovery, flexible pricing models, and granular configuration control.

For AI crawler operators

Discovery API

A new authenticated API endpoint allows verified crawlers to programmatically discover domains participating in Pay Per Crawl. Crawlers can use this to build optimized crawl queues, cache domain lists, and identify new participating sites. This eliminates the need to discover payable content through trial requests.

The API endpoint is GET https://crawlers-api.ai-audit.cfdata.org/charged_zones and requires Web Bot Auth authentication. Refer to Discover payable content for authentication steps, request parameters, and response schema.

Payment header signature requirement

…

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für Windows 2025.10.118.1 (Beta)

Der Windows WARP client 2025.10.118.1 ist als Beta verfügbar, behebt Local Domain Fallback ohne konfigurierten Fallback-Server, unterstützt im Proxy mode transparentes HTTP-Proxying und behebt Abstürze bei großen IPC-Nachrichten an den WARP-Daemon.

A new Beta release for the Windows WARP client is now available on the beta releases downloads page.

This release contains minor fixes and improvements.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly.
  • Proxy mode now supports transparent HTTP proxying in addition to CONNECT-based proxying.
  • Fixed an issue where sending large messages to the WARP daemon by Inter-Process Communication (IPC) could cause WARP to crash and result in service interruptions.

Known issues …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP client für macOS 2025.10.118.1 (Beta)

Der macOS WARP client 2025.10.118.1 ist als Beta verfügbar, behebt Local Domain Fallback ohne konfigurierten Fallback-Server und unterstützt im Proxy mode transparentes HTTP-Proxying.

A new Beta release for the macOS WARP client is now available on the beta releases downloads page.

This release contains minor fixes and improvements.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly.
  • Proxy mode now supports transparent HTTP proxying in addition to CONNECT-based proxying.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Schnellere Cold Starts für Python Workers

Python Workers starten durch einen beim Deployment erstellten Memory-Snapshot deutlich schneller, laut Benchmark etwa um den Faktor 10 gegenüber einem Start ohne Snapshot.

Python Workers now feature improved cold start performance, reducing initialization time for new Worker instances. This improvement is particularly noticeable for Workers with larger dependency sets or complex initialization logic.

Every time you deploy a Python Worker, a memory snapshot is captured after the top level of the Worker is executed. This snapshot captures all imports, including package imports that are often costly to load. The memory snapshot is loaded when the Worker is first started, avoiding the need to reload the Python runtime and all dependencies on each cold start.

We set up a benchmark that imports common packages (httpx ↗︎, fastapi ↗︎ and pydantic ↗︎) to see how Python Workers stack up against other platforms:

Platform

Mean Cold Start (ms)

Cloudflare Python Workers

1027

AWS Lambda

2502

Google Cloud Run

3069

These benchmarks run continuously. You can view the results and the methodology on our benchmark page ↗︎.

In additional testing, we have found that without any memory snapshot, the cold start for this benchmark takes around 10 seconds, so this change improves cold start performance by roughly a factor of 10.

To get started with Python Workers, check out our Python Workers overview.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Einfache Python-Paketverwaltung mit Pywrangler

Mit dem neuen Tool Pywrangler werden in der pyproject.toml angegebene, Workers-kompatible Python-Pakete automatisch installiert und beim Deployment mit dem Worker gebündelt.

We are introducing a brand new tool called Pywrangler, which simplifies package management in Python Workers by automatically installing Workers-compatible Python packages into your project.

With Pywrangler, you specify your Worker's Python dependencies in your pyproject.toml file:

[project]
name = "python-beautifulsoup-worker"
version = "0.1.0"
description = "A simple Worker using beautifulsoup4"
requires-python = ">=3.12"
dependencies = [
    "beautifulsoup4"
]

[dependency-groups]
dev = [
  "workers-py",
  "workers-runtime-sdk"
]

You can then develop and deploy your Worker using the following commands:

uv run pywrangler dev
uv run pywrangler deploy

Pywrangler automatically downloads and vendors the necessary packages for your Worker, and these packages are bundled with the Worker when you deploy.

Consult the Python packages documentation for full details on Pywrangler and Python package management in Workers.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Wrangler-Konfiguration mit Vite-Plugin optional

Beim Cloudflare Vite-Plugin ist für reine Assets-Seiten keine Wrangler-Konfigurationsdatei mehr nötig, da das Plugin sinnvolle Standardwerte erzeugt; SPAs benötigen weiterhin assets.not_found_handling.

When using the Cloudflare Vite plugin to build and deploy Workers, a Wrangler configuration file is now optional for assets-only (static) sites. If no wrangler.toml, wrangler.json, or wrangler.jsonc file is found, the plugin generates sensible defaults for an assets-only site. The name is based on the package.json or the project directory name, and the compatibility_date uses the latest date supported by your installed Miniflare version.

This allows easier setup for static sites using Vite. Note that SPAs will still need to set assets.not_found_handling to single-page-application ↗︎ in order to function correctly.

Originalquelle(öffnet in neuem Tab)Problem melden