Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Remote-Bindings allgemein verfügbar

Remote-Bindings sind jetzt allgemein in Wrangler, Vite und Vitest verfügbar, sodass lokale Worker auf bereitgestellte Ressourcen wie R2 und D1 zugreifen können.

Three months ago we announced the public beta of remote bindings for local development. Now, we're excited to say that it's available for everyone in Wrangler, Vite, and Vitest without using an experimental flag!

With remote bindings, you can now connect to deployed resources like R2 buckets and D1 databases while running Worker code on your local machine. This means you can test your local code changes against real data and services, without the overhead of deploying for each iteration.

Example configuration

To enable remote bindings, add "remote" : true to each binding that you want to rely on a remote resource running on Cloudflare:

{
	"name": "my-worker",
	// Set this to today's date
	"compatibility_date": "2026-10-11",

	"r2_buckets": [
		{
			"bucket_name": "screenshots-bucket",
			"binding": "screenshots_bucket",
			"remote": true,
		},
	],
}
name = "my-worker"
# Set this to today's date
compatibility_date = "2026-10-11"

[[r2_buckets]]
bucket_name = "screenshots-bucket"
binding = "screenshots_bucket"
remote = true
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

DNS: DNS-Firewall-Analysen im Dashboard

DNS-Firewall-Analysen sind jetzt direkt im Cloudflare-Dashboard verfügbar, mit vier interaktiven Panels, Filtern und bis zu 62 Tagen historischer Daten.

What's New

Access GraphQL-powered DNS Firewall analytics directly in the Cloudflare dashboard.

DNS Firewall Analytics UI

Explore Four Interactive Panels

  • Query summary: Describes trends over time, segmented by dimensions.
  • Query statistics: Describes totals, cached/uncached queries, and processing/response times.
  • DNS queries by data center: Describes global view and the top 10 data centers.
  • Top query statistics: Shows a breakdown by key dimensions, with search and expand options (up to top 100 items).

Additional features:

  • Apply filters and time ranges once. Changes reflect across all panels.
  • Filter by dimensions like query name, query type, cluster, data center, protocol (UDP/TCP), IP version, response code/reason, and more.
  • Access up to 62 days of historical data with flexible intervals.

Availability

Available to all DNS Firewall customers as part of their existing subscription.

Where to Find It

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update zu Argo CD, DataEase und Sitecore

Neue WAF-Regeln adressieren Schwachstellen in Argo CD, DataEase und Sitecore, die Informationsoffenlegung und Remote Code Execution ermöglichen.

This week's update

This week's focus highlights newly disclosed vulnerabilities in DevOps tooling, data visualization platforms, and enterprise CMS solutions. These issues include sensitive information disclosure and remote code execution, putting organizations at risk of credential leakage, unauthorized access, and full system compromise.

Key Findings

  • Argo CD (CVE-2025-55190): Exposure of sensitive information could allow attackers to access credential data stored in configurations, potentially leading to compromise of Kubernetes workloads and secrets.

  • DataEase (CVE-2025-57773): Insufficient input validation enables JNDI injection and insecure deserialization, resulting in remote code execution (RCE). Successful exploitation grants attackers control over the application server.

  • Sitecore (CVE-2025-53694): A sensitive information disclosure flaw allows unauthorized access to confidential information stored in Sitecore deployments, raising the risk of data breaches and privilege escalation.

Impact

These vulnerabilities expose organizations to serious risks, including credential theft, unauthorized access, and full system compromise. Argo CD's flaw may expose Kubernetes secrets, DataEase exploitation could give attackers remote execution capabilities, and Sitecore's disclosure issue increases the likelihood of sensitive data leakage and business impact. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: Regionale Verarbeitung in Deutschland, Indien oder Australien

Email-security-Kunden können beim Onboarding einer Domain per MX, BCC oder Journaling den Verarbeitungsort Deutschland, Indien oder Australien wählen, wobei die globale Verarbeitung weiterhin Standard bleibt.

We’re excited to announce that Email security customers can now choose their preferred mail processing location directly from the UI when onboarding a domain. This feature is available for the following onboarding methods: MX, BCC, and Journaling.

What’s new

Customers can now select where their email is processed. The following regions are supported:

  • Germany
  • India
  • Australia

Global processing remains the default option, providing flexibility to meet both compliance requirements or operational preferences.

How to use it

When onboarding a domain with MX, BCC, or Journaling:

  1. Select the desired processing location (Germany, India, or Australia).
  2. The UI will display updated processing addresses specific to that region.
  3. For MX onboarding, if your domain is managed by Cloudflare, you can automatically update MX records directly from the UI.

Availability

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

What’s next

We’re expanding the list of processing locations to match our Data Localization Suite (DLS) footprint, giving customers the broadest set of regional options in the market without the complexity of self-hosting.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

DNS-Filterung für private Netzwerk-Onramps mit Gateway

Magic-WAN- und WARP-Connector-Nutzer können DNS-Verkehr nun über die gemeinsamen Resolver-IPs 172.64.36.1 und 172.64.36.2 sicher zum Gateway-Resolver leiten, ohne das öffentliche Internet zu nutzen, und dabei Source Internal IP in Resolver-Richtlinien verwenden.

Magic WAN and WARP Connector users can now securely route their DNS traffic to the Gateway resolver without exposing traffic to the public Internet.

Routing DNS traffic to the Gateway resolver allows DNS resolution and filtering for traffic coming from private networks while preserving source internal IP visibility. This ensures Magic WAN users have full integration with our Cloudflare One features, including Internal DNS and hostname-based policies.

To configure DNS filtering, change your Magic WAN or WARP Connector DNS settings to use Cloudflare's shared resolver IPs, 172.64.36.1 and 172.64.36.2. Once you configure DNS resolution and filtering, you can use Source Internal IP as a traffic selector in your resolver policies for routing private DNS traffic to your Internal DNS.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

D1 wiederholt schreibgeschützte Abfragen automatisch

D1 erkennt schreibgeschützte Abfragen (SELECT, EXPLAIN, WITH) und versucht sie bei wiederholbaren Fehlern bis zu zweimal erneut auszuführen, wobei die Anzahl der Versuche in der Antwort-Metadaten-Eigenschaft total_attempts steht.

D1 now detects read-only queries and automatically attempts up to two retries to execute those queries in the event of failures with retryable errors. You can access the number of execution attempts in the returned response metadata property total_attempts.

At the moment, only read-only queries are retried, that is, queries containing only the following SQLite keywords: SELECT, EXPLAIN, WITH. Queries containing any SQLite keyword ↗︎ that leads to database writes are not retried.

The retry success ratio among read-only retryable errors varies from 5% all the way up to 95%, depending on the underlying error and its duration (like network errors or other internal errors).

The retry success ratio among all retryable errors is lower, indicating that there are write-queries that could be retried. Therefore, we recommend D1 users to continue applying retries in their own code for queries that are not read-only but are idempotent according to the business logic of the application.

D1 automatically query retries success ratio …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Worker-Rollback jetzt für die letzten 100 Versionen

Für Worker-Rollbacks stehen nun die 100 statt bisher 10 letzten Versionen zur Verfügung, die sich aktivieren oder per Gradual Deployments mit dem neuesten Code kombinieren lassen.

The number of recent versions available for a Worker rollback has been increased from 10 to 100.

This allows you to:

  • Promote any of the 100 most recent versions to be the active deployment.

  • Split traffic using gradual deployments between your latest code and any of the 100 most recent versions.

You can do this through the Cloudflare dashboard or with Wrangler's rollback command

Learn more about versioned deployments and rollbacks.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Log Explorer mit Kontext-Sprungfunktionen

Im Log Explorer können Nutzer nun direkt aus Suchergebnissen zu Investigate, Dokumentation und Zero-Trust-Richtlinien springen.

Directly from Log Search results, customers can pivot to other parts of the Cloudflare dashboard to immediately take action as a result of their investigation.

From the http_requests or fw_events dataset results, right click on an IP Address or JA3 Fingerprint to pivot to the Investigate portal to lookup the reputation of an IP address or JA3 fingerprint.

Investigate IP address

Easily learn about error codes by linking directly to our documentation from the EdgeResponseStatus or OriginResponseStatus fields.

View documentation

From the gateway_http dataset, click on a policyid to link directly to the Zero Trust dashboard to review or make changes to a specific Gateway policy.

View policy

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Neue Tabellenansicht im Log Explorer

Die Ergebnisse-Tabellenansicht im Log Search wurde mit Funktionen zum Hinzufügen/Entfernen von Spalten, Sortieren und Kopieren von Werten verbessert.

The results table view of Log Search has been updated with additional functionality and a more streamlined user experience. Users can now easily:

  • Remove/add columns.
  • Resize columns.
  • Sort columns.
  • Copy values from any field.

New results table view

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.1.0 und workers-ai-provider v2.0.0 mit AI SDK v5

Das Agents SDK 0.1.0 ist vollständig mit AI SDK v5 kompatibel und bringt automatische Nachrichtenmigration, verbessertes Streaming, Tool-Bestätigung und erweiterte React Hooks, außerdem wurde workers-ai-provider v2.0.0 für AI SDK v5 aktualisiert.

We've shipped a new release for the Agents SDK ↗︎ bringing full compatibility with AI SDK v5 ↗︎ and introducing automatic message migration that handles all legacy formats transparently.

This release includes improved streaming and tool support, tool confirmation detection (for "human in the loop" systems), enhanced React hooks with automatic tool resolution, improved error handling for streaming responses, and seamless migration utilities that work behind the scenes.

This makes it ideal for building production AI chat interfaces with Cloudflare Workers AI models, agent workflows, human-in-the-loop systems, or any application requiring reliable message handling across SDK versions — all while maintaining backward compatibility.

Additionally, we've updated workers-ai-provider v2.0.0, the official provider for Cloudflare Workers AI models, to be compatible with AI SDK v5.

useAgentChat(options)

Creates a new chat interface with enhanced v5 capabilities.

// Basic chat setup
const { messages, sendMessage, addToolResult } = useAgentChat({
	agent,
	experimental_automaticToolResolution: true,
	tools,
});

// With custom tool confirmation
const chat = useAgentChat({
	agent,
	experimental_automaticToolResolution: true,
	toolsRequiringConfirmation: ["dangerousOperation"],
});

Automatic Tool Resolution

…

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Aktualisierter „Built with Cloudflare“-Button

Der „Built with Cloudflare“-Button wurde überarbeitet, damit er sich leichter in READMEs, Blogposts und andere Seiten einbetten lässt.

We've updated our "Built with Cloudflare" button to make it easier to share that you're building on Cloudflare with the world. Embed it in your project's README, blog post, or wherever you want to let people know.

Built with Cloudflare

Check out the documentation for usage information.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Static Sites ohne Konfigurationsdatei auf Workers deployen

Beim Ausführen von wrangler deploy [directory] ohne Konfigurationsdatei führt Wrangler nun mit interaktiven Abfragen durch das Deployment und erzeugt automatisch eine wrangler.jsonc.

Deploying static site to Workers is now easier. When you run wrangler deploy [directory] or wrangler deploy --assets [directory] without an existing configuration file, Wrangler CLI now guides you through the deployment process with interactive prompts.

Before and after

Before: Required remembering multiple flags and parameters

wrangler deploy --assets ./dist --compatibility-date 2025-09-09 --name my-project

After: Simple directory deployment with guided setup

wrangler deploy dist
# Interactive prompts handle the rest as shown in the example flow below

What's new

Interactive prompts for missing configuration:

  • Wrangler detects when you're trying to deploy a directory of static assets
  • Prompts you to confirm the deployment type
  • Asks for a project name (with smart defaults)
  • Automatically sets the compatibility date to today

Automatic configuration generation:

  • Creates a wrangler.jsonc file with your deployment settings
  • Stores your choices for future deployments
  • Eliminates the need to remember complex command-line flags

Example workflow

# Deploy your built static site
wrangler deploy dist

# Wrangler will prompt: …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Cloudflare WAN: Benutzerdefinierte IKE ID für IPsec-Tunnel

Magic-WAN-Kunden können für IPsec-Tunnel nun per API eine benutzerdefinierte IKE ID festlegen, was zusammen mit VeloCloud-SD-WAN-Geräten eine Hochverfügbarkeitskonfiguration ermöglicht.

Now, Magic WAN customers can configure a custom IKE ID for their IPsec tunnels. Customers that are using Magic WAN and a VeloCloud SD-WAN device together can utilize this new feature to create a high availability configuration.

This feature is available via API only. Customers can read the Magic WAN documentation to learn more about the Custom IKE ID feature and the API call to configure it.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update für Next.js, ScriptCase und mehr

WAF-Regeln für Next.js SSRF, ScriptCase Admin-Reset und Command Execution sowie generische Injection-Erkennungen wurden hinzugefügt.

This week's update

This week’s focus highlights newly disclosed vulnerabilities in web frameworks, enterprise applications, and widely deployed CMS plugins. The vulnerabilities include SSRF, authentication bypass, arbitrary file upload, and remote code execution (RCE), exposing organizations to high-impact risks such as unauthorized access, system compromise, and potential data exposure. In addition, security rule enhancements have been deployed to cover general command injection and server-side injection attacks, further strengthening protections.

Key Findings

  • Next.js (CVE-2025-57822): Improper handling of redirects in custom middleware can lead to server-side request forgery (SSRF) when user-supplied headers are forwarded. Attackers could exploit this to access internal services or cloud metadata endpoints. The issue has been resolved in versions 14.2.32 and 15.4.7. Developers using custom middleware should upgrade and verify proper redirect handling in next() calls.

  • ScriptCase (CVE-2025-47227, CVE-2025-47228): In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), two vulnerabilities allow attackers to reset admin accounts and execute system commands, potentially leading to full compromise of affected deployments. …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Erinnerungen an Zwei-Faktor-Backup-Codes

Cloudflare erinnert Nutzer nun regelmäßig daran, ihre Backup-Codes für die Zwei-Faktor-Authentifizierung sicher zu speichern, um Sperren zu vermeiden.

Two-factor authentication is the best way to help protect your account from account takeovers, but if you lose your second factor, you could be locked out of your account. Lock outs are one of the top reasons customers contact Cloudflare support, and our policies often don't allow us to bypass two-factor authentication for customers that are locked out. Today we are releasing an improvement where Cloudflare will periodically remind you to securely save your backup codes so you don't get locked out in the future.

For more information

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Bidirektionale Tunnel-Health-Checks funktionieren mit allen Magic On-Ramps

Bei einer Hochverfügbarkeitskonfiguration besteht ein bidirektionaler Health Check nun, wenn das Antwortpaket über einen beliebigen Tunnel zurückkommt und nicht mehr nur über denselben Tunnel wie das Hinpaket.

All bidirectional tunnel health check return packets are accepted by any Magic on-ramp.

Previously, when a Magic tunnel had a bidirectional health check configured, the bidirectional health check would pass when the return packets came back to Cloudflare over the same tunnel that was traversed by the forward packets.

There are SD-WAN devices, like VeloCloud, that do not offer controls to steer traffic over one tunnel versus another in a high availability tunnel configuration.

Now, when a Magic tunnel has a bidirectional health check configured, the bidirectional health check will pass when the return packet traverses over any tunnel in a high availability configuration.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

EmbeddingGemma von Google jetzt auf Workers AI

Das mehrsprachige Embedding-Modell @cf/google/embeddinggemma-300m mit 300M Parametern ist auf Workers AI verfügbar und lässt sich auch in AI Search für RAG-Pipelines auswählen.

We're excited to be a launch partner alongside Google ↗︎ to bring their newest embedding model, EmbeddingGemma, to Workers AI that delivers best-in-class performance for its size, enabling RAG and semantic search use cases.

@cf/google/embeddinggemma-300m is a 300M parameter embedding model from Google, built from Gemma 3 and the same research used to create Gemini models. This multilingual model supports 100+ languages, making it ideal for RAG systems, semantic search, content classification, and clustering tasks.

Using EmbeddingGemma in AI Search: Now you can leverage EmbeddingGemma directly through AI Search for your RAG pipelines. EmbeddingGemma's multilingual capabilities make it perfect for global applications that need to understand and retrieve content across different languages with exceptional accuracy.

To use EmbeddingGemma for your AI Search projects:

  1. Go to Create in the AI Search dashboard ↗︎
  2. Follow the setup flow for your new RAG instance
  3. In the Generate Index step, open up More embedding models and select @cf/google/embeddinggemma-300m as your embedding model
  4. Complete the setup to create an AI Search

Try it out and let us know what you think!

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Höheres Limit für statische Assets bei Workers

Bezahlte Nutzer und Workers for Platforms können nun bis zu 100.000 statt 20.000 statische Assets pro Worker-Version hochladen, wofür Wrangler 4.34.0 oder neuer nötig ist.

You can now upload up to 100,000 static assets per Worker version

  • Paid and Workers for Platforms users can now upload up to 100,000 static assets per Worker version, a 5x increase from the previous limit of 20,000.
  • Customers on the free plan still have the same limit as before — 20,000 static assets per version of your Worker
  • The individual file size limit of 25 MiB remains unchanged for all customers.

This increase allows you to build larger applications with more static assets without hitting limits.

Wrangler

To take advantage of the increased limits, you must use Wrangler version 4.34.0 or higher. Earlier versions of Wrangler will continue to enforce the previous 20,000 file limit.

Learn more

For more information about Workers static assets, see the Static Assets documentation and Platform Limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue, einfachere REST API für Cloudflare Workers (Beta)

Workers, Versions und Deployments lassen sich nun in einer neuen ressourcenorientierten Beta-API als getrennte Ressourcen verwalten, unterstützt im Terraform-Provider und im Cloudflare TypeScript SDK.

You can now manage Workers, Versions, and Deployments as separate resources with a new, resource-oriented API (Beta).

This new API is supported in the Cloudflare Terraform provider ↗︎ and the Cloudflare Typescript SDK ↗︎, allowing platform teams to manage a Worker's infrastructure in Terraform, while development teams handle code deployments from a separate repository or workflow. We also designed this API with AI agents in mind, as a clear, predictable structure is essential for them to reliably build, test, and deploy applications.

Try it out

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Notfallupdate für Sitecore-Schwachstellen

Dringende WAF-Regeln blockieren Remote Code Execution und Cache-Poisoning in Sitecore XM/XP (CVE-2025-53690, -53691, -53693).

This week's update

This week, new critical vulnerabilities were disclosed in Sitecore’s Sitecore Experience Manager (XM), Sitecore Experience Platform (XP), specifically versions 9.0 through 9.3, and 10.0 through 10.4. These flaws are caused by unsafe data deserialization and code reflection, leaving affected systems at high risk of exploitation.

Key Findings

  • CVE-2025-53690: Remote Code Execution through Insecure Deserialization
  • CVE-2025-53691: Remote Code Execution through Insecure Deserialization
  • CVE-2025-53693: HTML Cache Poisoning through Unsafe Reflections

Impact

Exploitation could allow attackers to execute arbitrary code remotely on the affected system and conduct cache poisoning attacks, potentially leading to further compromise. Applying the latest vendor-released solution without delay is strongly recommended.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...0ee2c15e

100878

Sitecore - Remote Code Execution - CVE:CVE-2025-53691

N/A

Block

This is a new detection

Cloudflare Managed Ruleset

...7c5b669c

100631

Sitecore - Cache Poisoning - CVE:CVE-2025-53693

N/A

Block

This is a new detection

Cloudflare Managed Ruleset

...6c410240

100879

Sitecore - Remote Code Execution - CVE:CVE-2025-53690

N/A

Block

This is a new detection

Originalquelle(öffnet in neuem Tab)Problem melden