Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Browser Rendering: Playwright GA, Stagehand (Beta), höhere Limits

Playwright-Support in Browser Rendering ist nun allgemein verfügbar (Playwright v1.55), Stagehand wird als Beta unterstützt, und die Limits für bezahlte Pläne bei REST API und Browser Sessions wurden verdreifacht.

We’re shipping three updates to Browser Rendering:

  • Playwright support is now Generally Available and synced with Playwright v1.55 ↗︎, giving you a stable foundation for critical automation and AI-agent workflows.
  • We’re also adding Stagehand support (Beta) so you can combine code with natural language instructions to build more resilient automations.
  • Finally, we’ve tripled limits for paid plans across both the REST API and Browser Sessions to help you scale.

To get started with Stagehand, refer to the Stagehand example that uses Stagehand and Workers AI to search for a movie on this example movie directory ↗︎, extract its details using natural language (title, year, rating, duration, and genre), and return the information along with a screenshot of the webpage.

Stagehand examplets

const stagehand = new Stagehand({
	env: "LOCAL",
	localBrowserLaunchOptions: { cdpUrl: endpointURLString(env.BROWSER) },
	llmClient: new WorkersAIClient(env.AI),
	verbose: 1,
});

await stagehand.init(); …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search (ehemals AutoRAG) mit mehr Modellen

AutoRAG heißt jetzt AI Search und unterstützt über im AI Gateway hinterlegte Provider-Keys auch Modelle von Anbietern wie OpenAI und Anthropic für Embedding und Inferenz.

AutoRAG is now AI Search! The new name marks a new and bigger mission: to make world-class search infrastructure available to every developer and business.

With AI Search you can now use models from different providers like OpenAI and Anthropic. By attaching your provider keys to the AI Gateway linked to your AI Search instance, you can use many more models for both embedding and inference.

To use AI Search with other model providers:

  1. Add provider keys to AI Gateway
    1. Go to AI > AI Gateway in the dashboard.
    2. Select or create an AI gateway.
    3. In Provider Keys, choose your provider, click Add, and enter the key.
  2. Connect a gateway to AI Search: When creating a new AI Search, select the AI Gateway with your provider keys. For an existing AI Search, go to Settings and switch to a gateway that has your keys under Resources.
  3. Select models: Embedding models are only available to be changed when creating a new AI Search. Generation model can be selected when creating a new AI Search and can be changed at any time in Settings.

Once configured, your AI Search instance will be able to reference models available through your AI Gateway when making a /ai-search request:

export default {
  async fetch(request, env) {
    
    // Query your AI Search instance with a natural language question to an OpenAI model …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 Data Catalog unterstützt jetzt Compaction

R2 Data Catalog kann Apache-Iceberg-Tabellen nun automatisch per Compaction verdichten, um kleine Dateien zusammenzuführen und die Abfrageleistung zu verbessern, aktivierbar im Dashboard oder per Wrangler.

You can now enable automatic compaction for Apache Iceberg ↗︎ tables in R2 Data Catalog to improve query performance.

Compaction is the process of taking a group of small files and combining them into fewer larger files. This is an important maintenance operation as it helps ensure that query performance remains consistent by reducing the number of files that needs to be scanned.

To enable automatic compaction in R2 Data Catalog, find it under R2 Data Catalog in your R2 bucket settings in the dashboard.

compaction-dash

Or with Wrangler, run:

npx wrangler r2 bucket catalog compaction enable <BUCKET_NAME>  --target-size 128 --token <API_TOKEN>

To get started with compaction, check out manage catalogs. For best practices and limitations, refer to about compaction.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Container: Mehr gleichzeitige Instanzen und höhere Ressourcenlimits

Für gleichzeitig laufende Container-Instanzen gelten höhere Limits von 400 GiB Speicher, 100 vCPU und 2 TB Disk statt bisher 40 GiB, 20 vCPU und 100 GB.

You can now run more Containers concurrently with higher limits on CPU, memory, and disk.

Limit

New Limit

Previous Limit

Memory for concurrent live Container instances

400GiB

40GiB

vCPU for concurrent live Container instances

100

20

Disk for concurrent live Container instances

2TB

100GB

You can now run 1000 instances of the dev instance type, 400 instances of basic, or 100 instances of standard concurrently.

This opens up new possibilities for running larger-scale workloads on Containers.

See the getting started guide to deploy your first Container, and the limits documentation for more details on the available instance types and limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Anmeldung mit GitHub bei Cloudflare verfügbar

Cloudflare bietet jetzt die Anmeldung mit GitHub an, verfügbar für alle Nutzer mit verifizierter E-Mail-Adresse ohne SSO.

Cloudflare has launched sign in with GitHub as a log in option. This feature is available to all users with a verified email address who are not using SSO. To use it, simply click on the Sign in with GitHub button on the dashboard login page. You will be logged in with your primary GitHub email address.

For more information

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

SSO jetzt für alle Cloudflare-Nutzer kostenlos

Single Sign-on ist jetzt für alle Nutzer kostenlos verfügbar und kann direkt über die API konfiguriert werden, ohne Support-Kontakt.

Single sign-on (SSO) streamlines the process of logging into Cloudflare for Enterprise customers who manage a custom email domain and manage their own identity provider. Instead of managing a password and two-factor authentication credentials directly for Cloudflare, SSO lets you reuse your existing login infrastructure to seamlessly log in. SSO also provides additional security opportunities such as device health checks which are not available natively within Cloudflare.

Historically, SSO was only available for Enterprise accounts. Today, we are announcing that we are making SSO available to all users for free. We have also added the ability to directly manage SSO configurations using the API. This removes the previous requirement to contact support to configure SSO.

For more information

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF: Notfall-Regel für GoAnywhere MFT-Schwachstelle

Eine neue WAF-Regel blockiert die Deserialisierungs-Schwachstelle GoAnywhere MFT (CVE-2025-10035), die Command Injection ermöglichen kann.

This week highlights a critical vendor-specific vulnerability: a deserialization flaw in the License Servlet of Fortra’s GoAnywhere MFT. By forging a license response signature, an attacker can trigger deserialization of arbitrary objects, potentially leading to command injection.

Key Findings

  • GoAnywhere MFT (CVE-2025-10035): Deserialization vulnerability in the License Servlet that allows attackers with a forged license response signature to deserialize arbitrary objects, potentially resulting in command injection.

Impact

GoAnywhere MFT (CVE-2025-10035): Exploitation enables attackers to escalate privileges or achieve remote code execution via command injection.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...e08b39f3

100787

Fortra GoAnywhere - Auth Bypass - CVE:CVE-2025-10035

N/A

Block

This is a New Detection

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: Feedback zu ungültigen Einreichungen

Nutzer erhalten nun automatisch E-Mail-Benachrichtigungen bei ungültigen Einreichungen an Submission-Aliase, abschaltbar in den Einstellungen, und ein neues Dashboard zeigt, welche Nutzer Schulung benötigen.

Email security relies on your submissions to continuously improve our detection models. However, we often receive submissions in formats that cannot be ingested, such as incomplete EMLs, screenshots, or text files.

To ensure all customer feedback is actionable, we have launched two new features to manage invalid submissions sent to our team and user submission aliases:

  • Email Notifications: We now automatically notify users by email when they provide an invalid submission, educating them on the correct format. To disable notifications, go to Settings ↗︎ > Invalid submission emails and turn the feature off.

EmailSec-Invalid-Submissions-Toggle

  • Invalid Submission dashboard: You can quickly identify which users need education to provide valid submissions so Cloudflare can provide continuous protection.

EmailSec-Invalid-Submissions-Dashboard …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Besserer Support für mehrere Workers mit wrangler dev

Workers aus getrennten wrangler-dev-Sessions können jetzt lokal miteinander kommunizieren, sodass Service Bindings und Tail Workers auch über mehrere Dev-Befehle hinweg funktionieren.

You can run multiple Workers in a single dev command by passing multiple config files to wrangler dev:

wrangler dev --config ./web/wrangler.jsonc --config ./api/wrangler.jsonc

Previously, if you ran the command above and then also ran wrangler dev for a different Worker, the Workers running in separate wrangler dev sessions could not communicate with each other. This prevented you from being able to use Service Bindings ↗︎ and Tail Workers ↗︎ in local development, when running separate wrangler dev sessions.

Now, the following works as expected:

# Terminal 1: Run your application that includes both Web and API workers
wrangler dev --config ./web/wrangler.jsonc --config ./api/wrangler.jsonc

# Terminal 2: Run your auth worker separately
wrangler dev --config ./auth/wrangler.jsonc

These Workers can now communicate with each other across separate dev commands, regardless of your development setup.

./api/src/index.tsjs

export default {
	async fetch(request, env) {
		// This service binding call now works across dev commands
		const authorized = await env.AUTH.isAuthorized(request);

		if (!authorized) {
			return new Response("Unauthorized", { status: 401 });
		}

		return new Response("Hello from API Worker!", { status: 200 });
	},
};
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Besserer Support für mehrere Workers mit wrangler dev

Workers, die in getrennten wrangler-dev-Sitzungen laufen, können jetzt miteinander kommunizieren, sodass Service Bindings und Tail Workers auch über mehrere Dev-Befehle hinweg lokal funktionieren.

You can run multiple Workers in a single dev command by passing multiple config files to wrangler dev:

wrangler dev --config ./web/wrangler.jsonc --config ./api/wrangler.jsonc

Previously, if you ran the command above and then also ran wrangler dev for a different Worker, the Workers running in separate wrangler dev sessions could not communicate with each other. This prevented you from being able to use Service Bindings ↗︎ and Tail Workers ↗︎ in local development, when running separate wrangler dev sessions.

Now, the following works as expected:

# Terminal 1: Run your application that includes both Web and API workers
wrangler dev --config ./web/wrangler.jsonc --config ./api/wrangler.jsonc

# Terminal 2: Run your auth worker separately
wrangler dev --config ./auth/wrangler.jsonc

These Workers can now communicate with each other across separate dev commands, regardless of your development setup.

./api/src/index.tsjs

export default {
	async fetch(request, env) {
		// This service binding call now works across dev commands
		const authorized = await env.AUTH.isAuthorized(request);

		if (!authorized) {
			return new Response("Unauthorized", { status: 401 });
		}

		return new Response("Hello from API Worker!", { status: 200 });
	},
};
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: Browserbasiertes RDP ist allgemein verfügbar

Browserbasiertes RDP mit Cloudflare Access ist für alle Kunden allgemein verfügbar und bietet nun unter anderem IPv6-Targets, Magic WAN und WARP Connector als On-Ramps, bessere Fehlermeldungen und weltweite Tastaturunterstützung.

Browser-based RDP with Cloudflare Access is now generally available for all Cloudflare customers. It enables secure, remote Windows server access without VPNs or RDP clients.

Since we announced our open beta, we've made a few improvements:

  • Support for targets with IPv6.
  • Support for Magic WAN and WARP Connector as on-ramps.
  • More robust error messaging on the login page to help you if you encounter an issue.
  • Worldwide keyboard support. Whether your day-to-day is in Portuguese, Chinese, or something in between, your browser-based RDP experience will look and feel exactly like you are using a desktop RDP client.
  • Cleaned up some other miscellaneous issues, including but not limited to enhanced support for Entra ID accounts and support for usernames with spaces, quotes, and special characters.

As a refresher, here are some benefits browser-based RDP provides:

  • Control how users authenticate to internal RDP resources with single sign-on (SSO), multi-factor authentication (MFA), and granular access policies. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update mit Azure- und Skyvern-Schwachstellen

Die WAF-Regeln wurden um Erkennungen für Azure Privilege Escalation (CVE-2025-54914), Skyvern SSTI/RCE (CVE-2025-49619) sowie verbesserte SQLi- und SSRF-Abdeckung erweitert.

This week emphasizes two critical vendor-specific vulnerabilities: a full elevation-of-privilege in Microsoft Azure Networking (CVE-2025-54914) and a server-side template injection (SSTI) leading to remote code execution (RCE) in Skyvern (CVE-2025-49619). These are complemented by enhancements in generic detections (SQLi, SSRF) to improve baseline coverage.

Key Findings

  • Azure (CVE-2025-54914): Vulnerability in Azure Networking allowing elevation of privileges.

  • Skyvern (CVE-2025-49619): Skyvern ≤ 0.1.85 has a server-side template injection (SSTI) vulnerability in its Prompt field (workflow blocks) via Jinja2. Authenticated users with low privileges can get remote code execution (blind).

  • Generic SQLi / SSRF improvements: Expanded rule coverage to detect obfuscated SQL injection patterns and SSRF across host, local, and cloud contexts.

Impact

These vulnerabilities allow attackers to escalate privileges or execute code under conditions where previously they could not:

  • Azure CVE-2025-54914 enables an attacker from the network with no credentials to gain high-level access within Azure Networking; could lead to full compromise of networking components.

  • Skyvern CVE-2025-49619 allows authenticated users with minimal privilege to exploit SSTI for remote code execution, undermining isolation of workflow components.

  • The improvements for SQLi and SSRF reduce risk from common injection and request-based attacks.

Ruleset …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue Metrics-Ansicht in AutoRAG

AutoRAG enthält einen neuen Metrics-Tab, der Indexierung, die Nutzung von ai-search gegenüber search und die am häufigsten abgerufenen Dateien anzeigt.

AutoRAG now includes a Metrics tab that shows how your data is indexed and searched. Get a clear view of the health of your indexing pipeline, compare usage between ai-search and search, and see which files are retrieved most often.

Metrics

You can find these metrics within each AutoRAG instance:

  • Indexing: Track how files are ingested and see status changes over time.
  • Search breakdown: Compare usage between ai-search and search endpoints.
  • Top file retrievals: Identify which files are most frequently retrieved in a given period.

Try it today in AutoRAG.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Rate Limiting in Workers ist allgemein verfügbar

Das ratelimit-Binding für Rate Limiting in Workers ist jetzt GA und für Produktionslasten empfohlen, während bestehende Deployments mit dem unsafe-Binding weiterlaufen.

Rate Limiting within Cloudflare Workers is now Generally Available (GA).

The ratelimit binding is now stable and recommended for all production workloads. Existing deployments using the unsafe binding will continue to function to allow for a smooth transition.

For more details, refer to Workers Rate Limiting documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Panic Recovery für Rust Workers

Rust Workers erholen sich ab workers-rs Version 0.6.5 automatisch von Panics, wobei laufende Anfragen einen 500-Fehler liefern, künftige Anfragen aber normal bearbeitet werden.

In workers-rs ↗︎, Rust panics were previously non-recoverable. A panic would put the Worker into an invalid state, and further function calls could result in memory overflows or exceptions.

Now, when a panic occurs, in-flight requests will throw 500 errors, but the Worker will automatically and instantly recover for future requests.

This ensures more reliable deployments. Automatic panic recovery is enabled for all new workers-rs deployments as of version 0.6.5, with no configuration required.

Fixing Rust Panics with Wasm Bindgen

Rust Workers are built with Wasm Bindgen, which treats panics as non-recoverable. After a panic, the entire Wasm application is considered to be in an invalid state.

We now attach a default panic handler in Rust:

std::panic::set_hook(Box::new(move |panic_info| {
  hook_impl(panic_info);
}));

Which is registered by default in the JS initialization:

import { setPanicHook } from "./index.js";
setPanicHook(function (err) {
	console.error("Panic handler!", err);
});

When a panic occurs, we reset the Wasm state to revert the Wasm application to how it was when the application started.

Resetting VM State in Wasm Bindgen

…

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Cloudflare Tunnel: Hostname-Routing für private und öffentliche Apps

Privater Traffic lässt sich nun anhand von Hostnamen oder Domains statt nur per IP oder CIDR an Cloudflare Tunnel routen, kostenlos für alle Cloudflare One Kunden.

You can now route private traffic to Cloudflare Tunnel based on a hostname or domain, moving beyond the limitations of IP-based routing. This new capability is free for all Cloudflare One customers.

Previously, Tunnel routes could only be defined by IP address or CIDR range. This created a challenge for modern applications with dynamic or ephemeral IP addresses, often forcing administrators to maintain complex and brittle IP lists.

Hostname-based routing in Cloudflare Tunnel

What’s new:

  • Hostname & Domain Routing: Create routes for individual hostnames (e.g., payroll.acme.local) or entire domains (e.g., *.acme.local) and direct their traffic to a specific Tunnel.
  • Simplified Zero Trust Policies: Build resilient policies in Cloudflare Access and Gateway using stable hostnames, making it dramatically easier to apply per-resource authorization for your private applications.
  • Precise Egress Control: Route traffic for public hostnames (e.g., bank.example.com) through a specific Tunnel to enforce a dedicated source IP, solving the IP allowlist problem for third-party services. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Mehr vCPU für Workers Builds in bezahlten Plänen

Workers Builds bieten in bezahlten Plänen jetzt 4 statt 2 vCPU, wodurch insbesondere Multi-Thread-Builds mit Tools wie esbuild und webpack schneller laufen, während die übrigen Limits unverändert bleiben.

We recently increased the available disk space from 8 GB to 20 GB for all plans. Building on that improvement, we’re now doubling the CPU power available for paid plans — from 2 vCPU to 4 vCPU.

These changes continue our focus on making Workers Builds faster and more reliable.

Metric

Free Plan

Paid Plans

CPU

2 vCPU

4 vCPU

Performance Improvements

  • Fast build times: Even single-threaded workloads benefit from having more vCPUs
  • 2x faster multi-threaded builds: Tools like esbuild ↗︎ and webpack ↗︎ can now utilize additional cores, delivering near-linear performance scaling

All other build limits — including memory, build minutes, and timeout remain unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Hostname-basiertes Routing für Cloudflare Tunnel

Cloudflare Tunnel unterstützt nun Routing nach Hostname oder Domain statt nur nach IP-Adresse; dies ist für alle Cloudflare-One-Kunden kostenlos.

You can now route private traffic to Cloudflare Tunnel based on a hostname or domain, moving beyond the limitations of IP-based routing. This new capability is free for all Cloudflare One customers.

Previously, Tunnel routes could only be defined by IP address or CIDR range. This created a challenge for modern applications with dynamic or ephemeral IP addresses, often forcing administrators to maintain complex and brittle IP lists.

Hostname-based routing in Cloudflare Tunnel

What’s new:

  • Hostname & Domain Routing: Create routes for individual hostnames (e.g., payroll.acme.local) or entire domains (e.g., *.acme.local) and direct their traffic to a specific Tunnel.
  • Simplified Zero Trust Policies: Build resilient policies in Cloudflare Access and Gateway using stable hostnames, making it dramatically easier to apply per-resource authorization for your private applications.
  • Precise Egress Control: Route traffic for public hostnames (e.g., bank.example.com) through a specific Tunnel to enforce a dedicated source IP, solving the IP allowlist problem for third-party services. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Preview URLs für Workers sind jetzt standardmäßig Opt-in

Preview URLs von Workers sind nun standardmäßig deaktiviert und müssen bewusst aktiviert werden, und für bestehende Workers mit deaktivierter workers.dev-Subdomain wurden sie einmalig abgeschaltet.

To prevent the accidental exposure of applications, we've updated how Worker preview URLs (<PREVIEW>-<WORKER_NAME>.<SUBDOMAIN>.workers.dev) are handled. We made this change to ensure preview URLs are only active when intentionally configured, improving the default security posture of your Workers.

One-Time Update for Workers with workers.dev Disabled

We performed a one-time update to disable preview URLs for existing Workers where the workers.dev subdomain was also disabled.

Because preview URLs were historically enabled by default, users who had intentionally disabled their workers.dev route may not have realized their Worker was still accessible at a separate preview URL. This update was performed to ensure that using a preview URL is always an intentional, opt-in choice.

If your Worker was affected, its preview URL (<PREVIEW>-<WORKER_NAME>.<SUBDOMAIN>.workers.dev) will now direct to an informational page explaining this change.

How to Re-enable Your Preview URL …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Neue KI-gestützte Suche im Zero Trust Dashboard

Das Zero Trust Dashboard bietet eine KI-gestützte Suche über Ressourcen, Seiten und Produkte sowie den KI-Agenten Cloudy für Fragen zu Cloudflare Zero Trust und einen neuen Tab für zuletzt verwendete Suchen.

Zero Trust Dashboard has a brand new, AI-powered search functionality. You can search your account by resources (applications, policies, device profiles, settings, etc.), pages, products, and more.

Example search results in the Zero Trust dashboard

Ask Cloudy — You can also ask Cloudy, our AI agent, questions about Cloudflare Zero Trust. Cloudy is trained on our developer documentation and implementation guides, so it can tell you how to configure functionality, best practices, and can make recommendations.

Cloudy can then stay open with you as you move between pages to build configuration or answer more questions.

Find Recents — Recent searches and Cloudy questions also have a new tab under Zero Trust Overview.

Originalquelle(öffnet in neuem Tab)Problem melden