Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Workers programmatisch per Vite-Plugin konfigurieren

Das Cloudflare Vite-Plugin bietet eine neue config-Option, mit der sich Worker-Einstellungen direkt in der Vite-Konfiguration definieren oder aus einer Wrangler-Konfigurationsdatei geladene Werte anpassen lassen.

The Cloudflare Vite plugin now supports programmatic configuration of Workers without a Wrangler configuration file. You can use the config option to define Worker settings directly in your Vite configuration, or to modify existing configuration loaded from a Wrangler config file. This is particularly useful when integrating with other build tools or frameworks, as it allows them to control Worker configuration without needing users to manage a separate config file.

The config option

The Vite plugin's new config option accepts either a partial configuration object or a function that receives the current configuration and returns overrides. This option is applied after any config file is loaded, allowing the plugin to override specific values or define Worker configuration entirely in code.

Example usage

Setting config to an object to provide configuration values that merge with defaults and config file settings:

vite.config.tsts

import { defineConfig } from "vite";
import { cloudflare } from "@cloudflare/vite-plugin";

export default defineConfig({
	plugins: [
		cloudflare({
			config: {
				name: "my-worker",
				compatibility_flags: ["nodejs_compat"],
				send_email: [
					{
						name: "EMAIL",
					},
				],
			},
		}),
	],
});

Use a function to modify the existing configuration:

vite.config.tsts

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Payload-Limit auf 1 MB erhöht

Cloudflare WAF prüft nun bei allen Tarifen Anfrage-Payloads bis zu 1 MB, um die Erkennung von React RCE zu verbessern; die Änderung wurde später teilweise zurückgenommen.

Cloudflare WAF now inspects request-payload size of up to 1 MB across all plans to enhance our detection capabilities for React RCE (CVE-2025-55182).

Key Findings

React payloads commonly have a default maximum size of 1 MB. Cloudflare WAF previously inspected up to 128 KB on Enterprise plans, with even lower limits on other plans.

Update: We later reinstated the maximum request-payload size the Cloudflare WAF inspects. Refer to Updating the WAF maximum payload values for details.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Payload-Grenzwerte angepasst

Cloudflare stellt die maximale Payload-Größe für die WAF-Prüfung wieder auf 128 KB für Enterprise-Zonen ein; zahlende Kunden können auf Wunsch 1 MB erhalten.

We are reinstating the maximum request-payload size the Cloudflare WAF inspects, with WAF on Enterprise zones inspecting up to 128 KB.

Key Findings

On December 5, 2025, we initially attempted to increase the maximum WAF payload limit to 1 MB across all plans. However, an automatic rollout for all customers proved impractical because the increase led to a surge in false positives for existing managed rules.

This issue was particularly notable within the Cloudflare Managed Ruleset and the Cloudflare OWASP Core Ruleset, impacting customer traffic.

Impact

Customers on paid plans can increase the limit to 1 MB for any of their zones by contacting Cloudflare Support. Free zones are already protected up to 1 MB and do not require any action.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform v5.14.0 verfügbar

Der Terraform-Provider für Cloudflare wurde in Version 5.14.0 veröffentlicht, mit Fehlerbehebungen, Stabilisierung weiterer Ressourcen und einer Abkündigung für api_shield_discovery_operation.

Earlier this year, we announced the launch of the new Terraform v5 Provider. We are aware of the high number of issues reported by the Cloudflare community related to the v5 release. We have committed to releasing improvements on a 2-3 week cadence ↗︎ to ensure its stability and reliability, including the v5.14 release. We have also pivoted from an issue-to-issue approach to a resource-per-resource approach ↗︎ - we will be focusing on specific resources to not only stabilize the resource but also ensure it is migration-friendly for those migrating from v4 to v5.

Thank you for continuing to raise issues. They make our provider stronger and help us build products that reflect your needs.

This release includes bug fixes, the stabilization of even more popular resources, and more.

Deprecation notice

Resource affected: api_shield_discovery_operation

Cloudflare continuously discovers and updates API endpoints and web assets of your web applications. To improve the maintainability of these dynamic resources, we are working on reducing the need to actively engage with discovered operations. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Hyperdrive: Remote-Datenbanken bei lokaler Entwicklung mit wrangler dev

Mit wrangler dev kann man sich nun über localConnectionString oder eine Umgebungsvariable direkt mit Remote-Datenbanken und TLS-Datenbanken verbinden, ohne wrangler dev --remote zu nutzen.

You can now connect directly to remote databases and databases requiring TLS with wrangler dev. This lets you run your Worker code locally while connecting to remote databases, without needing to use wrangler dev --remote.

The localConnectionString field and CLOUDFLARE_HYPERDRIVE_LOCAL_CONNECTION_STRING_<BINDING_NAME> environment variable can be used to configure the connection string used by wrangler dev.

{
  "hyperdrive": [
    {
      "binding": "HYPERDRIVE",
      "id": "your-hyperdrive-id",
      "localConnectionString": "postgres://user:password@remote-host.example.com:5432/database?sslmode=require"
    }
  ]
}

Learn more about local development with Hyperdrive.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Access-Schutz für Workers erstellt wiederverwendbare Access-Richtlinien

Der Access-Schutz per Klick für Workers legt jetzt wiederverwendbare Cloudflare Access-Richtlinien an, etwa eine gemeinsame Richtlinie für alle Preview-URLs eines Accounts, statt anwendungsspezifischer Richtlinien.

Workers applications now use reusable Cloudflare Access policies to reduce duplication and simplify access management across multiple Workers.

Previously, enabling Cloudflare Access on a Worker created per-application policies, unique to each application. Now, we create reusable policies that can be shared across applications:

  • Preview URLs: All Workers preview URLs share a single "Cloudflare Workers Preview URLs" policy across your account. This policy is automatically created the first time you enable Access on any preview URL. By sharing a single policy across all preview URLs, you can configure access rules once and have them apply company-wide to all Workers which protect preview URLs. This makes it much easier to manage who can access preview environments without having to update individual policies for each Worker. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: „Reclassifications“ heißen jetzt „Submissions“

In Email Security werden die Begriffe „Reclassify“ und „Reclassifications“ in „Submit“ und „Submissions“ umbenannt, wobei eine Submission die ursprüngliche Disposition der Mails nicht ändert und nur zur Optimierung künftiger Kampagnenvarianten dient.

We have updated the terminology “Reclassify” and “Reclassifications” to “Submit” and “Submissions” respectively. This update more accurately reflects the outcome of providing these items to Cloudflare.

Submissions are leveraged to tune future variants of campaigns. To respect data sanctity, providing a submission does not change the original disposition of the emails submitted.

nav\_example

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Regel auf CVE-2025-55182 aktualisiert

Die Beschreibung der WAF-Regel wurde aktualisiert, um sie explizit auf React – RCE – CVE-2025-55182 zu beziehen; die Erkennungslogik bleibt unverändert.

The WAF rule deployed yesterday to block unsafe deserialization-based RCE has been updated. The rule description now reads “React – RCE – CVE-2025-55182”, explicitly mapping to the recently disclosed React Server Components vulnerability. Detection logic remains unchanged.

Key Findings

Rule description updated to reference React – RCE – CVE-2025-55182 while retaining existing unsafe-deserialization detection.

Impact

Improved classification and traceability with no change to coverage against remote code execution attempts.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...5fb92fba

N/A

React - RCE - CVE:CVE-2025-55182

N/A

Block

Rule metadata description changed. Detection unchanged.

Cloudflare Free Ruleset

...99702280

N/A

React - RCE - CVE:CVE-2025-55182

N/A

Block

Rule metadata description changed. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Neue WAF-Regel gegen RCE-Schwachstelle

Eine neue WAF-Regel blockiert bösartige POST-Anfragen mit unsicheren Deserialisierungsmustern, die eine kritische RCE-Schwachstelle in verbreiteten Web-Frameworks ausnutzen.

This week's emergency release introduces a new rule to block a critical RCE vulnerability in widely-used web frameworks through unsafe deserialization patterns.

Key Findings

New WAF rule deployed for RCE Generic Framework to block malicious POST requests containing unsafe deserialization patterns. If successfully exploited, this vulnerability allows attackers with network access via HTTP to execute arbitrary code remotely.

Impact

  • Successful exploitation allows unauthenticated attackers to execute arbitrary code remotely through crafted serialization payloads, enabling complete system compromise, data exfiltration, and potential lateral movement within affected environments.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...5fb92fba

N/A

RCE Generic - Framework

N/A

Block

This is a new detection.

Cloudflare Free Ruleset

...99702280

N/A

RCE Generic - Framework

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Updates für Monsta FTP und XSS

Neue WAF-Erkennung für Remote Code Execution in Monsta FTP (CVE-2025-34299) sowie Zusammenführung einer XSS-Beta-Regel in die bestehende Regel zur verbesserten Abdeckung.

This week’s release introduces new detections for remote code execution attempts targeting Monsta FTP (CVE-2025-34299), alongside improvements to an existing XSS detection to enhance coverage.

Key Findings

  • CVE-2025-34299 is a critical remote code execution flaw in Monsta FTP, arising from improper handling of user-supplied parameters within the file-handling interface. Certain builds allow crafted requests to bypass sanitization and reach backend PHP functions that execute arbitrary commands. Attackers can send manipulated parameters through the web panel to trigger command execution within the application’s runtime environment.

Impact

If exploited, the vulnerability enables full remote command execution on the underlying server, allowing takeover of the hosting environment, unauthorized file access, and potential lateral movement. As the flaw can be triggered without authentication on exposed Monsta FTP instances, it represents a severe risk for publicly reachable deployments.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...a4fcc8a8

N/A

Monsta FTP - Remote Code Execution - CVE:CVE-2025-34299

Log

Block

This is a new detection

Cloudflare Managed Ruleset

...b7492846

N/A

XSS - JS Context Escape - Beta

Log

Block

This rule is merged into the original rule "XSS - JS Context Escape" (ID: ...7a3769d3)

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK Version 0.2.24

Das Agents SDK 0.2.24 bringt für AIChatAgent fortsetzbares Streaming, eine überarbeitete MCPClientManager-API mit registerServer() und connectToServer(), einen Standard-JSON-Schema-Validator im MCP-Client und Korrekturen bei Schedules.

The latest release of @cloudflare/agents ↗︎ brings resumable streaming, significant MCP client improvements, and critical fixes for schedules and Durable Object lifecycle management.

Resumable streaming

AIChatAgent now supports resumable streaming, allowing clients to reconnect and continue receiving streamed responses without losing data. This is useful for:

  • Long-running AI responses
  • Users on unreliable networks
  • Users switching between devices mid-conversation
  • Background tasks where users navigate away and return
  • Real-time collaboration where multiple clients need to stay in sync

Streams are maintained across page refreshes, broken connections, and syncing across open tabs and devices.

Other improvements

  • Default JSON schema validator added to MCP client
  • Schedules ↗︎ can now safely destroy the agent

MCP client API improvements

The MCPClientManager API has been redesigned for better clarity and control:

  • New registerServer() method: Register MCP servers without immediately connecting
  • New connectToServer() method: Establish connections to registered servers
  • Improved reconnect logic: restoreConnectionsFromStorage() now properly handles failed connections
// Register a server to Agent …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

FLUX.2 [dev] jetzt auf Workers AI verfügbar

Workers AI bietet nun das Bildmodell FLUX.2 [dev] von Black Forest Labs an, das bis zu 4 Eingabebilder (512x512) unterstützt, Multipart-Formulardaten als Eingabe verlangt und langsamer als andere Bildmodelle sein dürfte.

We've partnered with Black Forest Labs (BFL) to bring their latest FLUX.2 [dev] model to Workers AI! This model excels in generating high-fidelity images with physical world grounding, multi-language support, and digital asset creation. You can also create specific super images with granular controls like JSON prompting.

Read the BFL blog ↗︎ to learn more about the model itself. Read our Cloudflare blog ↗︎ to see the model in action, or try it out yourself on our multi modal playground ↗︎.

Pricing documentation is available on the model page or pricing page. Note, we expect to drop pricing in the next few days after iterating on the model performance.

Workers AI Platform specifics

The model hosted on Workers AI is able to support up to 4 image inputs (512x512 per input image). Note, this image model is one of the most powerful in the catalog and is expected to be slower than the other image models we currently support. One catch to look out for is that this model takes multipart form data inputs, even if you just have a prompt.

With the REST API, the multipart form data input looks like this:

curl --request POST \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

Cache: Audit-Logs für Cache-Purge-Ereignisse

Cache-Purge-Ereignisse können nun über das Dashboard oder die API in detaillierten Audit-Logs eingesehen werden, einschließlich der Anfrageinhalte und des ausführenden Akteurs.

You can now review detailed audit logs for cache purge events, giving you visibility into what purge requests were sent, what they contained, and by whom. Audit your purge requests via the Dashboard or API for all purge methods:

  • Purge everything
  • List of prefixes
  • List of tags
  • List of hosts
  • List of files

Example

The detailed audit payload is visible within the Cloudflare Dashboard (under Manage Account > Audit Logs) and via the API. Below is an example of the Audit Logs v2 payload structure:

{
  "action": {
    "result": "success",
    "type": "create"
  },
  "actor": {
    "id": "1234567890abcdef",
    "email": "user@example.com",
    "type": "user"
  },
  "resource": {
    "product": "purge_cache",
    "request": {
      "files": [
        "https://example.com/images/logo.png",
        "https://example.com/css/styles.css"
      ]
    }
  },
  "zone": {
    "id": "023e105f4ecef8ad9ca31a8372d0c353",
    "name": "example.com"
  }
}

Get started

To get started, refer to the Audit Logs documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Automatische Zombie-API-Erkennung

API Shield erkennt jetzt automatisch Zombie-Endpunkte, die 32 Tage lang keinen Traffic erhalten haben, und kennzeichnet sie mit dem Risiko-Label cf-risk-zombie.

API Shield now automatically detects zombie endpoints — saved endpoints that have not received traffic for an extended period. When detected, the cf-risk-zombie risk label is applied.

The scan runs daily alongside existing risk scans. Endpoints are labeled after 32 days without traffic.

Zombie endpoints may indicate deprecated or forgotten API surface area that could pose a security risk. Review these endpoints and consider removing them from Endpoint Management if they are no longer in use. Also consider using a fallthrough rule to prevent communication with endpoints removed from Endpoint Management.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Verbesserungen für FortiWeb und PHP

Die WAF-Erkennung für die FortiWeb-Schwachstelle CVE-2025-64446 wurde verbessert, und zwei PHP-Wrapper-Injection-Beta-Regeln wurden in bestehende Regeln integriert.

This week highlights enhancements to detection signatures improving coverage for vulnerabilities in FortiWeb, linked to CVE-2025-64446, alongside new detection logic expanding protection against PHP Wrapper Injection techniques.

Key Findings

This vulnerability enables an unauthenticated attacker to bypass access controls by abusing the CGIINFO header. The latest update strengthens detection logic to ensure a reliable identification of crafted requests attempting to exploit this flaw.

Impact

  • FortiWeb (CVE-2025-64446): Exploitation allows a remote unauthenticated adversary to circumvent authentication mechanisms by sending a manipulated CGIINFO header to FortiWeb’s backend CGI handler. Successful exploitation grants unintended access to restricted administrative functionality, potentially enabling configuration tampering or system-level actions.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...4e2e1a2e

N/A

FortiWeb - Authentication Bypass via CGIINFO Header - CVE:CVE-2025-64446

Log

Block

This is a new detection

Cloudflare Managed Ruleset

...b6c44ed5

N/A

PHP Wrapper Injection - Body - Beta

Log

Disabled

This rule has been merged into the original rule "PHP Wrapper Injection - Body" (ID:...1a3e521e)

Cloudflare Managed Ruleset

...900f4015

N/A

PHP Wrapper Injection - URI - Beta

Log

Disabled …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2-Buckets in Containers einbinden

Containers unterstützen jetzt das Einbinden von R2-Buckets als FUSE-Volumes, sodass Anwendungen mit R2 über normale Dateisystemoperationen arbeiten können.

Containers now support mounting R2 buckets as FUSE (Filesystem in Userspace) volumes, allowing applications to interact with R2 using standard filesystem operations.

Common use cases include:

  • Bootstrapping containers with datasets, models, or dependencies for sandboxes and agent environments
  • Persisting user configuration or application state without managing downloads
  • Accessing large static files without bloating container images or downloading at startup

FUSE adapters like tigrisfs ↗︎, s3fs ↗︎, and gcsfuse ↗︎ can be installed in your container image and configured to mount buckets at startup.

FROM alpine:3.20

# Install FUSE and dependencies
RUN apk update && \
    apk add --no-cache ca-certificates fuse curl bash

# Install tigrisfs
RUN ARCH=$(uname -m) && \
    if [ "$ARCH" = "x86_64" ]; then ARCH="amd64"; fi && \
    if [ "$ARCH" = "aarch64" ]; then ARCH="arm64"; fi && \
    VERSION=$(curl -s https://api.github.com/repos/tigrisdata/tigrisfs/releases/latest | grep -o '"tag_name": "[^"]*' | cut -d'"' -f4) && \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue CPU-Preise für Containers und Sandboxes

Die CPU-Zeit bei Containers und Sandboxes wird jetzt nach tatsächlicher Nutzung statt nach bereitgestellten Ressourcen abgerechnet, während Speicher- und Datenträgerpreise unverändert bleiben.

Containers and Sandboxes pricing for CPU time is now based on active usage only, instead of provisioned resources.

This means that you now pay less for Containers and Sandboxes.

An Example Before and After

Imagine running the standard-2 instance type for one hour, which can use up to 1 vCPU, but on average you use only 20% of your CPU capacity.

CPU-time is priced at $0.00002 per vCPU-second.

Previously, you would be charged for the CPU allocated to the instance multiplied by the time it was active, in this case 1 hour.

CPU cost would have been: $0.072 — 1 vCPU * 3600 seconds * $0.00002

Now, since you are only using 20% of your CPU capacity, your CPU cost is cut to 20% of the previous amount.

CPU cost is now: $0.0144 — 1 vCPU * 3600 seconds * $0.00002 * 20% utilization

This can significantly reduce costs for Containers and Sandboxes.

Note

Memory cost and disk pricing remain unchanged, and is still calculated based on provisioned resources.

See the documentation to learn more about Containers, Sandboxes, and associated pricing.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Höhere Limits für Umgebungsvariablen bei Workers Builds

Workers Builds unterstützt jetzt bis zu 64 Umgebungsvariablen mit je bis zu 5 KB, statt zuvor insgesamt 5 KB für alle Variablen.

Workers Builds now supports up to 64 environment variables, and each environment variable can be up to 5 KB in size. The previous limit was 5 KB total across all environment variables.

This change enables better support for complex build configurations, larger application settings, and more flexible CI/CD workflows.

For more details, refer to the build limits documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Besserer lokaler Deployment-Ablauf für Cloudflare Workers

wrangler deploy zeigt nun die Unterschiede zwischen lokaler Konfiguration und den Dashboard-Einstellungen an und bietet an, die lokale Konfigurationsdatei zu aktualisieren, statt Dashboard-Einstellungen ohne Hinweis zu überschreiben.

Until now, if a Worker had been previously deployed via the Cloudflare Dashboard ↗︎, a subsequent deployment done via the Cloudflare Workers CLI, Wrangler (through the deploy command), would allow the user to override the Worker's dashboard settings without providing details on what dashboard settings would be lost.

Now instead, wrangler deploy presents a helpful representation of the differences between the local configuration and the remote dashboard settings, and offers to update your local configuration file for you.

See example below showing a before and after for wrangler deploy when a local configuration is expected to override a Worker's dashboard settings:

Before

wrangler deploy run before the improved workflow

After

wrangler deploy run after the improved workflow …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Threat Insights in Threat Events verfügbar

Im Threat-Events-Platform sind nun Threat Insights für relevante Ereignisse verfügbar, die Analysten bei der Bedrohungssuche unterstützen und im Dashboard markiert werden.

The threat events platform now has threat insights available for some relevant parent events. Threat intelligence analyst users can access these insights for their threat hunting activity. Insights are also highlighted in the Cloudflare dashboard by a small lightning icon and the insights can refer to multiple, connected events, potentially part of the same attack or campaign and associated with the same threat actor.

For more information, refer to Analyze threat events.

Originalquelle(öffnet in neuem Tab)Problem melden