Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Application Security von Cloudflare

Security Center: Neue Application-Security-Berichte in der geschlossenen Beta

Der neue Application Security Report im Security Center ist in der Closed Beta verfügbar und bietet monatliche Cybersicherheits-Trends sowie einen Branchenvergleich für Enterprise-Zonen.

Cloudflare's new Application Security report, currently in Closed Beta, is now available in the dashboard.

Go to Security reports ↗

The reports are generated monthly and provide cyber security insights trends for all of the Enterprise zones in your Cloudflare account.

The reports also include an industry benchmark, comparing your cyber security landscape to peers in your industry.

Application Security report mock data

Learn more about the reports by referring to the Security Reports documentation.

Use the feedback survey link at the top of the page to help us improve the reports.

Application Security report survey

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF: Neue Regeln für verwaltete Rulesets

Cloudflare hat neue Erkennungsregeln für verwaltete Rulesets veröffentlicht, die Angriffe wie SSRF, SQLi, SSTI, Reverse Shells und Prototype Pollution besser abdecken.

This week we introduced several new detections across Cloudflare Managed Rulesets, expanding coverage for high-impact vulnerability classes such as SSRF, SQLi, SSTI, Reverse Shell attempts, and Prototype Pollution. These rules aim to improve protection against attacker-controlled payloads that exploit misconfigurations or unvalidated input in web applications.

Key Findings

New detections added for multiple exploit categories:

SSRF (Server-Side Request Forgery) — new rules targeting both local and cloud metadata abuse patterns (Beta).

SQL Injection (SQLi) — rules for common patterns, sleep/time-based injections, and string/wait function exploitation across headers and URIs.

SSTI (Server-Side Template Injection) — arithmetic-based probe detections introduced across URI, header, and body fields.

Reverse Shell and XXE payloads — enhanced heuristics for command execution and XML external entity misuse.

Prototype Pollution — new Beta rule identifying common JSON payload structures used in object prototype poisoning.

PHP Wrapper Injection and HTTP Parameter Pollution detections — to catch path traversal and multi-parameter manipulation attempts.

Anomaly Header Checks — detecting CRLF injection attempts in header names.

Impact

These updates help detect multi-vector payloads that blend SSRF + RCE or SQLi + SSTI attacks, especially in cloud-hosted applications with exposed metadata endpoints or unsafe template rendering. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für Windows 2025.9.173.1 (Beta)

Die Beta des Windows WARP-Clients bringt Path Maximum Transmission Unit Discovery (PMTUD), eine Verbindungsstatus-Meldung in der GUI bei instabilem Netz sowie Verbesserungen für Windows multi-user.

A new Beta release for the Windows WARP client is now available on the beta releases downloads page.

This release contains minor fixes, improvements, and new features including Path Maximum Transmission Unit Discovery (PMTUD). With PMTUD enabled, the client will dynamically adjust packet sizing to optimize connection performance. There is also a new connection status message in the GUI to inform users that the local network connection may be unstable. This will make it easier to debug connectivity issues.

Changes and improvements

  • Improvements for Windows multi-user to maintain the Global WARP override state when switching between users.
  • The GUI now displays the health of the tunnel and DNS connections by showing a connection status message when the network may be unstable. This will make it easier to debug connectivity issues.
  • Deleting registrations no longer returns an error when succeeding. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für macOS 2025.9.173.1 (Beta)

Die Beta des macOS WARP-Clients bringt Path Maximum Transmission Unit Discovery (PMTUD) und eine Verbindungsstatus-Meldung in der GUI bei instabilem Netz; das Löschen von Registrierungen meldet bei Erfolg keinen Fehler mehr.

A new Beta release for the macOS WARP client is now available on the beta releases downloads page.

This release contains minor fixes, improvements, and new features including Path Maximum Transmission Unit Discovery (PMTUD). With PMTUD enabled, the client will dynamically adjust packet sizing to optimize connection performance. There is also a new connection status message in the GUI to inform users that the local network connection may be unstable. This will make it easier to debug connectivity issues.

Changes and improvements

  • The GUI now displays the health of the tunnel and DNS connections by showing a connection status message when the network may be unstable. This will make it easier to debug connectivity issues.
  • Deleting registrations no longer returns an error when succeeding.
  • Path Maximum Transmission Unit Discovery (PMTUD) is now used to discover the effective MTU of the connection. This allows the client to improve connection performance optimized for the current network.

Known issues

  • macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.4 or later. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Durable Objects: Daten im Dashboard mit Data Studio (Beta) bearbeiten

Mit dem Data Studio lässt sich der Speicher von Durable Objects mit SQLite-Storage nun in einem UI-Editor im Cloudflare-Dashboard ansehen und beschreiben, ohne dafür einen Worker deployen zu müssen.

Screenshot of Durable Objects Data Studio

You can now view and write to each Durable Object's storage using a UI editor on the Cloudflare dashboard. Only Durable Objects using SQLite storage can use Data Studio.

Go to Durable Objects ↗

Data Studio unlocks easier data access with Durable Objects for prototyping application data models to debugging production storage usage. Before, querying your Durable Objects data required deploying a Worker.

To access a Durable Object, you can provide an object's unique name or ID generated by Cloudflare. Data Studio requires you to have at least the Workers Platform Admin role, and all queries are captured with audit logging for your security and compliance needs. Queries executed by Data Studio send requests to your remote, deployed objects and incur normal usage billing.

To learn more, visit the Data Studio documentation. If you have feedback or suggestions for the new Data Studio, please share your experience on Discord ↗︎

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

Load Balancing: Monitor-Gruppen für erweiterte Health-Checks

Load Balancing unterstützt nun Monitor-Gruppen, mit denen mehrere Health-Monitore zu einer logischen Gruppe kombiniert werden können, um die Verfügbarkeit von Anwendungen genauer zu beurteilen.

Cloudflare Load Balancing now supports Monitor Groups, a powerful new way to combine multiple health monitors into a single, logical group. This allows you to create sophisticated health checks that more accurately reflect the true availability of your applications by assessing multiple services at once.

With Monitor Groups, you can ensure that all critical components of an application are healthy before sending traffic to an origin pool, enabling smarter failover decisions and greater resilience. This feature is now available via the API for customers with an Enterprise Load Balancing subscription.

What you can do:

  • Combine Multiple Monitors: Group different health monitors (for example, HTTP, TCP) that check various application components, like a primary API gateway and a specific /login service.
  • Isolate Monitors for Observation: Mark a monitor as "monitoring only" to receive alerts and data without it affecting a pool's health status or traffic steering. This is perfect for testing new checks or observing non-critical dependencies.
  • Improve Steering Intelligence: Latency for Dynamic Steering is automatically averaged across all active monitors in a group, providing a more holistic view of an origin's performance. …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Header-Größenlimit auf 128 KB erhöht

Cloudflare erhöht das maximale HTTP-Header-Größenlimit für Anfragen und Antworten auf 128 KB und reduziert so 413- und 520-Fehler.

CDN now supports 128 KB request and response headers 🚀

We're excited to announce a significant increase in the maximum header size supported by Cloudflare's Content Delivery Network (CDN). Cloudflare now supports up to 128 KB for both request and response headers.

Previously, customers were limited to a total of 32 KB for request or response headers, with a maximum of 16 KB per individual header. Larger headers could cause requests to fail with HTTP 413 (Request Header Fields Too Large) errors.


What's new?

  • Support for large headers: You can now utilize much larger headers, whether as a single large header up to 128 KB or split over multiple headers.
  • Reduces 413 and 520 HTTP errors: This change drastically reduces the likelihood of customers encountering HTTP 413 errors from large request headers or HTTP 520 errors caused by oversized response headers, improving the overall reliability of your web applications.
  • Enhanced functionality: This is especially beneficial for applications that rely on:
    • A large number of cookies.
    • Large Content-Security-Policy (CSP) response headers.
    • Advanced use cases with Cloudflare Workers that generate large response headers.

This enhancement improves compatibility with Cloudflare's CDN, enabling more use cases that previously failed due to header size limits.

      • …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Erweiterte KI-Crawler-Metriken mit Drilldowns

AI Crawl Control bietet nun erweiterte Metriken, Zeitverlaufsdiagramme und CSV-Exporte mit Filtern nach Crawler, Kategorie, Betreiber, Host und Statuscode.

AI Crawl Control now provides enhanced metrics and CSV data exports to help you better understand AI crawler activity across your sites.

What's new

Track crawler requests over time

Visualize crawler activity patterns over time, and group data by different dimensions:

  • By Crawler — Track activity from individual AI crawlers (GPTBot, ClaudeBot, Bytespider)
  • By Category — Analyze crawler purpose or type
  • By Operator — Discover which companies (OpenAI, Anthropic, ByteDance) are crawling your site
  • By Host — Break down activity across multiple subdomains
  • By Status Code — Monitor HTTP response codes to crawlers (200s, 300s, 400s, 500s)

AI Crawl Control requests over time chart with grouping tabs

Interactive chart showing crawler requests over time with filterable dimensions

Analyze referrer data (Paid plans)

Identify traffic sources with referrer analytics:

  • View top referrers driving traffic to your site
  • Understand discovery patterns and content popularity from AI operators …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Single Sign-on im Dashboard verwaltbar

Cloudflare bietet jetzt eine neue Benutzeroberfläche im Dashboard, um die SSO-Konfiguration zu verwalten, zuvor war nur die API verfügbar.

Screenshot of new user experience for managing SSO

During Birthday Week, we announced that single sign-on (SSO) is available for free ↗︎ to everyone who signs in with a custom email domain and maintains a compatible identity provider ↗︎. SSO minimizes user friction around login and provides the strongest security posture available. At the time, this could only be configured using the API.

Today, we are launching a new user experience which allows users to manage their SSO configuration from within the Cloudflare dashboard. You can access this by going to Manage account > Members > Settings.

For more information

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF: Neue Regel gegen JinJava-Sandbox-Bypass

Eine neue WAF-Regel blockiert den Sandbox-Bypass JinJava (CVE-2025-59340), der zu Remote-Code-Ausführung führen kann.

This week’s highlights include a new JinJava rule targeting a sandbox-bypass flaw that could allow malicious template input to escape execution controls. The rule improves detection for unsafe template rendering paths.

Key Findings

New WAF rule deployed for JinJava (CVE-2025-59340) to block a sandbox bypass in the template engine that permits attacker-controlled type construction and arbitrary class instantiation; in vulnerable environments this can escalate to remote code execution and full server compromise.

Impact

  • CVE-2025-59340 — Exploitation enables attacker-supplied type descriptors / Jackson ObjectMapper abuse, allowing arbitrary class loading, file/URL access (LFI/SSRF primitives) and, with suitable gadget chains, potential remote code execution and system compromise.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...c04bab5f

100892

JinJava - SSTI - CVE:CVE-2025-59340

Log

Block

This is a New Detection

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway: Drei neue Domain-Kategorien unter Technology

Unter der Elternkategorie Technology gibt es die neuen Domain-Kategorien Keep Awake Software, Remote Access und Shareware/Freeware für besseres DNS-Filtering.

We have added three new domain categories under the Technology parent category, to better reflect online content and improve DNS filtering.

New categories added

Parent ID

Parent Name

Category ID

Category Name

26

Technology

194

Keep Awake Software

26

Technology

192

Remote Access

26

Technology

193

Shareware/Freeware

Refer to Gateway domain categories to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Worker-Startzeitlimit auf 1 Sekunde erhöht

Ein Worker darf jetzt bis zu 1 Sekunde zum Parsen und Ausführen seines globalen Scopes benötigen, zuvor lag das Limit bei 400 ms.

You can now upload a Worker that takes up 1 second to parse and execute its global scope. Previously, startup time was limited to 400 ms.

This allows you to run Workers that import more complex packages and execute more code prior to requests being handled.

For more information, see the documentation on Workers startup limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Full-Stack-Apps auf Workers mit Terraform deployen

Mit dem Cloudflare Terraform Provider v5.11.0 lassen sich Workers samt statischer Assets hochladen, indem man nur das Build-Verzeichnis angibt, ohne eigene Skripte für Manifest, Upload und Änderungserkennung.

You can now upload Workers with static assets (like HTML, CSS, JavaScript, images) with the Cloudflare Terraform provider v5.11.0 ↗︎, making it even easier to deploy and manage full-stack apps with IaC.

Previously, you couldn't use Terraform to upload static assets without writing custom scripts to handle generating an asset manifest, calling the Cloudflare API to upload assets in chunks, and handling change detection.

Now, you simply define the directory where your assets are built, and we handle the rest. Check out the examples for what this looks like in Terraform configuration.

You can get started today with the Cloudflare Terraform provider (v5.11.0) ↗︎, using either the existing cloudflare_workers_script resource ↗︎, or the beta cloudflare_worker_version resource ↗︎.

Examples

…

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workflows lassen sich jetzt mit Terraform verwalten

Der Cloudflare Terraform Provider v5.11.0 enthält die neue Ressource cloudflare_workflow, mit der sich Workflows per Terraform erstellen und verwalten lassen.

You can now create and manage Workflows using Terraform, now supported in the Cloudflare Terraform provider v5.11.0 ↗︎. Workflows allow you to build durable, multi-step applications -- without needing to worry about retrying failed tasks or managing infrastructure.

Now, you can deploy and manage Workflows through Terraform using the new cloudflare_workflow resource ↗︎:

resource "cloudflare_workflow" "my_workflow" {
  account_id    = var.account_id
  workflow_name = "my-workflow"
  class_name    = "MyWorkflow"
  script_name   = "my-worker"
}

Examples

Here are full examples of how to configure cloudflare_workflow in Terraform, using the existing cloudflare_workers_script resource ↗︎, and the beta cloudflare_worker_version resource ↗︎.

With cloudflare_workflow and cloudflare_workers_script

resource "cloudflare_workers_script" "workflow_worker" {
  account_id  = var.cloudflare_account_id
  script_name = "my-workflow-worker" …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für Linux 2025.8.779.0

Der Linux WARP-Client 2025.8.779.0 beschleunigt den Proxy mode mit SOCKS4, SOCK5 und HTTP CONNECT über einen L4-Tunnel und enthält einen aktualisierten öffentlichen Schlüssel für Linux-Pakete, der vor dem 4. Dezember 2025 erneuert werden muss, wenn er vor dem 12. September 2025 installiert wurde.

A new GA release for the Linux WARP client is now available on the stable releases downloads page.

This release contains significant fixes and improvements including an updated public key for Linux packages. The public key must be updated if it was installed before September 12, 2025 to ensure the repository remains functional after December 4, 2025. Instructions to make this update are available at pkg.cloudflareclient.com.

Changes and improvements

  • Proxy mode has been enhanced for even faster resolution. Proxy mode now supports SOCKS4, SOCK5, and HTTP CONNECT over an L4 tunnel with custom congestion control optimizations instead of the previous L3 tunnel to Cloudflare's network. This has more than doubled Proxy mode throughput in lab speed testing, by an order of magnitude in some cases. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für Windows 2025.8.779.0

Der Windows WARP-Client 2025.8.779.0 beschleunigt den Proxy mode über einen L4-Tunnel, erlaubt dort aber nur noch das MASQUE-Protokoll, sodass Geräteprofile mit Proxy mode und Wireguard die Verbindung verlieren, wenn sie nicht umgestellt werden.

A new GA release for the Windows WARP client is now available on the stable releases downloads page.

This release contains significant fixes and improvements.

Changes and improvements

  • Proxy mode has been enhanced for even faster resolution. Proxy mode now supports SOCKS4, SOCK5, and HTTP CONNECT over an L4 tunnel with custom congestion control optimizations instead of the previous L3 tunnel to Cloudflare's network. This has more than doubled Proxy mode throughput in lab speed testing, by an order of magnitude in some cases.

  • The MASQUE protocol is now the only protocol that can use Proxy mode. If you previously configured a device profile to use Proxy mode with Wireguard, you will need to select a new WARP mode or switch to the MASQUE protocol. Otherwise, all devices matching the profile will lose connectivity.

Known issues …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP-Client für macOS 2025.8.779.0

Der macOS WARP-Client 2025.8.779.0 beschleunigt den Proxy mode über einen L4-Tunnel, erlaubt dort aber nur noch das MASQUE-Protokoll, sodass Geräteprofile mit Proxy mode und Wireguard die Verbindung verlieren, wenn sie nicht umgestellt werden.

A new GA release for the macOS WARP client is now available on the stable releases downloads page.

This release contains significant fixes and improvements.

Changes and improvements

  • Proxy mode has been enhanced for even faster resolution. Proxy mode now supports SOCKS4, SOCK5, and HTTP CONNECT over an L4 tunnel with custom congestion control optimizations instead of the previous L3 tunnel to Cloudflare's network. This has more than doubled Proxy mode throughput in lab speed testing, by an order of magnitude in some cases.

  • The MASQUE protocol is now the only protocol that can use Proxy mode. If you previously configured a device profile to use Proxy mode with Wireguard, you will need to select a new WARP mode or switch to the MASQUE protocol. Otherwise, all devices matching the profile will lose connectivity.

Known issues

  • macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.4 or later. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue Übersichtsseite für Cloudflare Workers im Dashboard

Jeder Worker hat im Cloudflare-Dashboard nun eine Übersichtsseite mit Requests, Fehlern, CPU-Zeit, Bindings, letzten Versionen, vereinfachter Tab-Navigation und Hinweisen für nächste Schritte.

Screenshot of the Workers overview page in the Cloudflare dashboard

Each of your Workers now has a new overview page in the Cloudflare dashboard.

The goal is to make it easier to understand your Worker without digging through multiple tabs. Think of it as a new home base, a place to get a high-level overview on what's going on.

It's the first place you land when you open a Worker in the dashboard, and it gives you an immediate view of what’s going on. You can see requests, errors, and CPU time at a glance. You can view and add bindings, and see recent versions of your app, including who published them.

Navigation is also simpler, with visually distinct tabs at the top of the page. At the bottom right you'll find guided steps for what to do next that are based on the state of your Worker, such as adding a binding or connecting a custom domain.

We plan to add more here over time. Better insights, more controls, and ways to manage your Worker from one page.

If you have feedback or suggestions for the new Overview page or your Cloudflare Workers experience in general, we'd love to hear from you. Join the Cloudflare developer community on Discord ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF: Notfall-Update für kritische Cisco-Schwachstellen

Cloudflare hat Notfall-Regeln für mehrere kritische Cisco-Sicherheitslücken (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363) veröffentlicht, die Remote-Code-Ausführung ermöglichen können.

This week highlights multiple critical Cisco vulnerabilities (CVE-2025-20363, CVE-2025-20333, CVE-2025-20362). This flaw stems from improper input validation in HTTP(S) requests. An authenticated VPN user could send crafted requests to execute code as root, potentially compromising the device. The initial two rules were made available on September 28, with a third rule added today, October 7, for more robust protection.

  • Cisco (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363): Multiple vulnerabilities that could allow attackers to exploit unsafe deserialization and input validation flaws. Successful exploitation may result in arbitrary code execution, privilege escalation, or command injection on affected systems.

Impact

Cisco (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363): Exploitation enables attackers to escalate privileges or achieve remote code execution via command injection. Administrators are strongly advised to apply vendor updates immediately.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...3a4d1bd6

100788B

Cisco Secure Firewall Adaptive Security Appliance - Remote Code Execution - CVE:CVE-2025-20333, CVE:CVE-2025-20362, CVE:CVE-2025-20363

N/A

Block

This is a New Detection

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Automatische Erinnerungen für Backup-Codes

Cloudflare führt E-Mail- und In-App-Erinnerungen ein, die Nutzer dazu anhalten, Backup-Codes für die Zwei-Faktor-Authentifizierung herunterzuladen.

The most common reason users contact Cloudflare support is lost two-factor authentication (2FA) credentials. Cloudflare supports both app-based and hardware keys for 2FA, but you could lose access to your account if you lose these. Over the past few weeks, we have been rolling out email and in-product reminders that remind you to also download backup codes (sometimes called recovery keys) that can get you back into your account in the event you lose your 2FA credentials. Download your backup codes now by logging into Cloudflare, then navigating to Profile > Security & Authentication > Backup codes.

Sign-in security best practices

Cloudflare is critical infrastructure, and you should protect it as such. Please review the following best practices and make sure you are doing your part to secure your account.

  • Use a unique password for every website, including Cloudflare, and store it in a password manager like 1Password or Keeper. These services are cross-platform and simplify the process of managing secure passwords.
  • Use 2FA to make it harder for an attacker to get into your account in the event your password is leaked
  • Store your backup codes securely. A password manager is the best place since it keeps the backup codes encrypted, but you can also print them and put them somewhere safe in your home. …

Originalquelle(öffnet in neuem Tab)Problem melden