Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Core Platform von Cloudflare

Neue Rate-Limiting-Header für die API

Die Cloudflare-API liefert jetzt standardisierte Rate-Limiting-Header, und die neuesten SDKs weichen automatisch bei erreichten Limits aus.

Cloudflare's API now supports rate limiting headers using the pattern developed by the IETF draft on rate limiting ↗︎. This allows API consumers to know how many more calls are left until the rate limit is reached, as well as how long you will need to wait until more capacity is available.

Our SDKs automatically work with these new headers, backing off when rate limits are approached. There is no action required for users of the latest Cloudflare SDKs to take advantage of this.

As always, if you need any help with rate limits, please contact Support.

Changes

New Headers

Headers that are always returned:

  • Ratelimit: List of service limit items, composed of the limit name, the remaining quota (r) and the time next window resets (t). For example: "default";r=50;t=30
  • Ratelimit-Policy: List of quota policy items, composed of the policy name, the total quota (q) and the time window the quota applies to (w). For example: "burst";q=100;w=60

Returned only when a rate limit has been reached (error code: 429):

  • Retry-After: Number of Seconds until more capacity is available, rounded up

SDK Back offs

  • All of Cloudflare's latest SDKs will automatically respond to the headers, instituting a backoff when limits are approached.

GraphQL and Edge APIs

…

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Benutzerdefinierte Felder für Header und Cookies

Log Explorer unterstützt nun das Protokollieren und Filtern von Header- und Cookie-Feldern im http_requests-Datensatz über benutzerdefinierte Felder.

Log Explorer now supports logging and filtering on header or cookie fields in the http_requests dataset.

Create a custom field to log desired header or cookie values into the http_requests dataset and Log Explorer will import these as searchable fields. Once configured, use the custom SQL editor in Log Explorer to view or filter on these requests.

Edit Custom fields

For more details, refer to Headers and cookies.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Tunnel- und Networks-API liefert ab 1. Dezember 2025 keine gelöschten Ressourcen mehr

Ab dem 1. Dezember 2025 geben die List-Endpunkte der Cloudflare Tunnel API und der Zero Trust Networks API standardmäßig keine gelöschten Tunnel, Routen, Subnetze und virtuellen Netzwerke mehr zurück, und wer is_deleted=false bereits setzt, muss nichts tun.

Starting December 1, 2025, list endpoints for the Cloudflare Tunnel API and Zero Trust Networks API will no longer return deleted tunnels, routes, subnets and virtual networks by default. This change makes the API behavior more intuitive by only returning active resources unless otherwise specified.

No action is required if you already explicitly set is_deleted=false or if you only need to list active resources.

This change affects the following API endpoints:

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

API-Änderung: Gelöschte Ressourcen ausgeblendet

Ab dem 1. Dezember 2025 geben die Listen-Endpunkte der Cloudflare-Tunnel- und Netzwerke-API standardmäßig keine gelöschten Ressourcen mehr zurück.

Starting December 1, 2025, list endpoints for the Cloudflare Tunnel API and Zero Trust Networks API will no longer return deleted tunnels, routes, subnets and virtual networks by default. This change makes the API behavior more intuitive by only returning active resources unless otherwise specified.

No action is required if you already explicitly set is_deleted=false or if you only need to list active resources.

This change affects the following API endpoints:

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Überarbeitete Email-security-Rollen

Die Email-security-Rollen wurden granularer gefasst und haben keinen Lese- oder Schreibzugriff mehr auf andere Zero-Trust-Produkte, sodass für DLP oder RBI nun die Rolle Cloudflare Zero Trust nötig ist.

To provide more granular controls, we refined the existing roles for Email security and launched a new Email security role as well.

All Email security roles no longer have read or write access to any of the other Zero Trust products:

  • Email Configuration Admin
  • Email Integration Admin
  • Email security Read Only
  • Email security Analyst
  • Email security Policy Admin
  • Email security Reporting

To configure Data Loss Prevention (DLP) or Remote Browser Isolation (RBI), you now need to be an admin for the Zero Trust dashboard with the Cloudflare Zero Trust role. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update zu Fortinet FortiWeb Auth Bypass

Eine neue WAF-Regel erkennt den Authentifizierungs-Bypass in Fortinet FortiWeb (CVE-2025-52970); eine XSS-Regel-Metadatenbeschreibung wurde verfeinert.

This week's update

This week, a critical vulnerability was disclosed in Fortinet FortiWeb (versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and versions 7.0.10 and below), linked to improper parameter handling that could allow unauthorized access.

Key Findings

  • Fortinet FortiWeb (CVE-2025-52970): A vulnerability may allow an unauthenticated remote attacker with access to non-public information to log in as any existing user on the device via a specially crafted request.

Impact

Exploitation could allow an unauthenticated attacker to impersonate any existing user on the device, potentially enabling them to modify system settings or exfiltrate sensitive information, posing a serious security risk. Upgrading to the latest vendor-released version is strongly recommended.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...c49b7cf8

100586

Fortinet FortiWeb - Auth Bypass - CVE:CVE-2025-52970

Log

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...790c9dde

100136C

XSS - JavaScript - Headers and Body

N/A

N/A

Rule metadata description refined. Detection unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

WARP Diagnostic AI Analyzer in der Beta für alle Nutzer

Der neue KI-basierte WARP diagnostic analyzer steht als Beta im Cloudflare One Dashboard bereit und wertet WARP-Diagnoseprotokolle aus, um Auswirkungen, auffällige Ereignisse und empfohlene Schritte zur Behebung von Verbindungsproblemen zu nennen.

We're excited to share a new AI feature, the WARP diagnostic analyzer ↗︎, to help you troubleshoot and resolve WARP connectivity issues faster. This beta feature is now available in the Cloudflare One dashboard ↗︎ to all users. The AI analyzer makes it easier for you to identify the root cause of client connectivity issues by parsing remote captures of WARP diagnostic logs. The WARP diagnostic analyzer provides a summary of impact that may be experienced on the device, lists notable events that may contribute to performance issues, and recommended troubleshooting steps and articles to help you resolve these issues. Refer to WARP diagnostics analyzer (beta) to learn more about how to maximize using the WARP diagnostic analyzer to troubleshoot the WARP client.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

DEX MCP Server für Digital Experience Monitoring

Für DEX gibt es einen MCP-Server, mit dem Kunden per Frage Konnektivitäts- und Leistungsdaten aus der DEX API abrufen können und der für Free-, Pay-as-you-go- und Enterprise-Konten verfügbar ist.

Digital Experience Monitoring (DEX) provides visibility into device connectivity and performance across your Cloudflare SASE deployment.

We've released an MCP server (Model Context Protocol) ↗︎ for DEX.

The DEX MCP server is an AI tool that allows customers to ask a question like, "Show me the connectivity and performance metrics for the device used by carly‌@acme.com", and receive an answer that contains data from the DEX API.

Any Cloudflare One customer using a Free, Pay-as-you-go, or Enterprise account can access the DEX MCP Server. This feature is available to everyone.

Customers can test the new DEX MCP server in less than one minute. To learn more, read the DEX MCP server documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

Cache: Smart Tiered Cache fällt auf Generic zurück

Smart Tiered Cache fällt nun automatisch auf Generic Tiered Cache zurück, wenn der Standort des Ursprungs nicht ermittelt werden kann, was die Cache-Effizienz verbessert.

Smart Tiered Cache now falls back to Generic Tiered Cache when the origin location cannot be determined, improving cache precision for your content.

Previously, when Smart Tiered Cache was unable to select the optimal upper tier (such as when origins are masked by Anycast IPs), latency could be negatively impacted. This fallback now uses Generic Tiered Cache instead, providing better performance and cache efficiency.

How it works

When Smart Tiered Cache falls back to Generic Tiered Cache:

  1. Multiple upper-tiers: Uses all of Cloudflare's global data centers as a network of upper-tiers instead of a single optimal location.
  2. Distributed cache requests: Lower-tier data centers can query any available upper-tier for cached content.
  3. Improved global coverage: Provides better cache hit ratios across geographically distributed visitors.
  4. Automatic fallback: Seamlessly transitions when origin location cannot be determined, such as with Anycast-masked origins.

Benefits

  • Preserves high performance during fallback: Smart Tiered Cache now maintains strong cache efficiency even when optimal upper tier selection is not possible. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Notfallupdate für Next.js-Bildoptimierung

Notfall-WAF-Regeln blockieren gefährlichen Datei-Download und Cache-Poisoning in Next.js (CVE-2025-55173, CVE-2025-57752).

This week's update

This week, new critical vulnerabilities were disclosed in Next.js’s image optimization functionality, exposing a broad range of production environments to risks of data exposure and cache manipulation.

Key Findings

  • CVE-2025-55173: Arbitrary file download from the server via image optimization.

  • CVE-2025-57752: Cache poisoning leading to unauthorized data disclosure.

Impact

Exploitation could expose sensitive files, leak user or backend data, and undermine application trust. Given Next.js’s wide use, immediate patching and cache hardening are strongly advised.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...9ff4bfe3

100613

Next.js - Dangerous File Download - CVE:CVE-2025-55173

N/A

Block

This is a new detection

Cloudflare Managed Ruleset

...69b9ea7d

100616

Next.js - Information Disclosure - CVE:CVE-2025-57752

N/A

Block

This is a new detection

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform v5.9 verfügbar

Der Terraform-Provider v5.9 stabilisiert mehrere Ressourcen und führt die neue Ressource cloudflare_snippet ein, die cloudflare_snippets ersetzt.

Earlier this year, we announced the launch of the new Terraform v5 Provider. We are aware of the high number of issues ↗︎ reported by the Cloudflare community related to the v5 release. We have committed to releasing improvements on a 2 week cadence to ensure its stability and reliability, including the v5.9 release. We have also pivoted from an issue-to-issue approach to a resource-per-resource approach - we will be focusing on specific resources for every release, stabilizing the release, and closing all associated bugs with that resource before moving onto resolving migration issues.

Thank you for continuing to raise issues. We triage them weekly and they help make our products stronger.

This release includes a new resource, cloudflare_snippet, which replaces cloudflare_snippets. cloudflare_snippet is now considered deprecated but can still be used. Please utilize cloudflare_snippet as soon as possible.

Changes

  • Resources stabilized:
    • cloudflare_zone_setting
    • cloudflare_worker_script
    • cloudflare_worker_route
    • tiered_cache
  • NEW resource cloudflare_snippet which should be used in place of cloudflare_snippets. cloudflare_snippets is now deprecated. This enables the management of Cloudflare's snippet functionality through Terraform. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Shadow IT: Neues SaaS-Analytics-Dashboard

Das überarbeitete Shadow-IT-Dashboard zeigt, wer welche SaaS-Anwendungen nutzt und wie viele Daten übertragen werden, und erlaubt Freigabestatus wie Unreviewed, In Review, Approved und Unapproved, die auch in Gateway-HTTP-Richtlinien verwendet werden können.

Zero Trust has significantly upgraded its Shadow IT analytics, providing you with unprecedented visibility into your organizations use of SaaS tools. With this dashboard, you can review who is using an application and volumes of data transfer to the application.

You can review these metrics against application type, such as Artificial Intelligence or Social Media. You can also mark applications with an approval status, including Unreviewed, In Review, Approved, and Unapproved designating how they can be used in your organization.

Cloudflare One Analytics Dashboards

These application statuses can also be used in Gateway HTTP policies, so you can block, isolate, limit uploads and downloads, and more based on the application status.

Both the analytics and policies are accessible in the Cloudflare Zero Trust dashboard ↗︎, empowering organizations with better visibility and control.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Deepgram- und Leonardo-Partnermodelle auf Workers AI

Workers AI bietet neue Partnermodelle von Deepgram und Leonardo für Text-to-Speech, Speech-to-Text und Bildgenerierung sowie ein Turn-Detection-Modell zur Erkennung des Sprechendes.

New state-of-the-art models have landed on Workers AI! This time, we're introducing new partner models trained by our friends at Deepgram ↗︎ and Leonardo ↗︎, hosted on Workers AI infrastructure.

As well, we're introuding a new turn detection model that enables you to detect when someone is done speaking — useful for building voice agents!

Read the blog ↗︎ for more details and check out some of the new models on our platform:

  • @cf/deepgram/aura-1 is a text-to-speech model that allows you to input text and have it come to life in a customizable voice
  • @cf/deepgram/nova-3 is speech-to-text model that transcribes multilingual audio at a blazingly fast speed
  • @cf/pipecat-ai/smart-turn-v2 helps you detect when someone is done speaking
  • @cf/leonardo/lucid-origin is a text-to-image model that generates images with sharp graphic design, stunning full-HD renders, or highly specific creative direction
  • @cf/leonardo/phoenix-1.0 is a text-to-image model with exceptional prompt adherence and coherent text …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

AI Crawl Control mit erweiterten Analysen

AI Crawl Control ist jetzt allgemein verfügbar und bietet detaillierte Crawler-Statistiken sowie optionale HTTP-402-Antworten für blockierte KI-Crawler in kostenpflichtigen Plänen.

We improved AI crawler management with detailed analytics and introduced custom HTTP 402 responses for blocked crawlers. AI Audit has been renamed to AI Crawl Control and is now generally available.

Enhanced Crawlers tab:

  • View total allowed and blocked requests for each AI crawler
  • Trend charts show crawler activity over your selected time range per crawler

Updated AI Crawl Control table showing request counts and trend charts

Custom block responses (paid plans): You can now return HTTP 402 "Payment Required" responses when blocking AI crawlers, enabling direct communication with crawler operators about licensing terms.

For users on paid plans, when blocking AI crawlers you can configure:

  • Response code: Choose between 403 Forbidden or 402 Payment Required
  • Response body: Add a custom message with your licensing contact information

AI Crawl Control block response configuration interface

Example 402 response:

HTTP 402 Payment Required
Date: Mon, 24 Aug 2025 12:56:49 GMT
Content-type: application/json
Server: cloudflare
Cf-Ray: 967e8da599d0c3fa-EWR
Cf-Team: 2902f6db750000c3fa1e2ef400000001

{ …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

CASB: Neue Integrationen für ChatGPT, Claude und Gemini

Cloudflare CASB unterstützt nun per API und ohne Agenten die Plattformen OpenAI ChatGPT, Anthropic Claude und Google Gemini mit Posture Management, DLP-Erkennung in Anhängen und GenAI-spezifischen Einblicken.

Cloudflare CASB ↗︎ now supports three of the most widely used GenAI platforms — OpenAI ChatGPT, Anthropic Claude, and Google Gemini. These API-based integrations give security teams agentless visibility into posture, data, and compliance risks across their organization’s use of generative AI.

Cloudflare CASB showing selection of new findings for ChatGPT, Claude, and Gemini integrations.

Key capabilities

  • Agentless connections — connect ChatGPT, Claude, and Gemini tenants via API; no endpoint software required
  • Posture management — detect insecure settings and misconfigurations that could lead to data exposure
  • DLP detection — identify sensitive data in uploaded chat attachments or files
  • GenAI-specific insights — surface risks unique to each provider’s capabilities

Learn more

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Zugriff auf interne MCP-Server mit Cloudflare Access steuern

Self-hosted Applications in Cloudflare Access unterstützen nun OAuth für die MCP-Server-Authentifizierung, sodass der Zugriff auf interne MCP-Server per Access-Richtlinien beschränkt werden kann, auch in Verbindung mit MCP server portals.

You can now control who within your organization has access to internal MCP servers, by putting internal MCP servers behind Cloudflare Access.

Self-hosted applications in Cloudflare Access now support OAuth for MCP server authentication. This allows Cloudflare to delegate access from any self-hosted application to an MCP server via OAuth. The OAuth access token authorizes the MCP server to make requests to your self-hosted applications on behalf of the authorized user, using that user's specific permissions and scopes.

For example, if you have an MCP server designed for internal use within your organization, you can configure Access policies to ensure that only authorized users can access it, regardless of which MCP client they use. Support for internal, self-hosted MCP servers also works with MCP server portals, allowing you to provide a single MCP endpoint for multiple MCP servers. For more on MCP server portals, read the blog post ↗︎ on the Cloudflare Blog.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: MCP server portals in offener Beta

MCP server portals bündeln mehrere MCP-Server hinter einem HTTP-Endpunkt, erlauben pro Portal ausgewählte Tools und Prompt-Vorlagen und protokollieren Anfragen über Cloudflare Access, derzeit als offene Beta für alle Pläne.

MCP server portal

An MCP server portal centralizes multiple Model Context Protocol (MCP) servers onto a single HTTP endpoint. Key benefits include:

  • Streamlined access to multiple MCP servers: MCP server portals support both unauthenticated MCP servers as well as MCP servers secured using any third-party or custom OAuth provider. Users log in to the portal URL through Cloudflare Access and are prompted to authenticate separately to each server that requires OAuth.
  • Customized tools per portal: Admins can tailor an MCP portal to a particular use case by choosing the specific tools and prompt templates that they want to make available to users through the portal. This allows users to access a curated set of tools and prompts — the less external context exposed to the AI model, the better the AI responses tend to be.
  • Observability: Once the user's AI agent is connected to the portal, Cloudflare Access logs the individual requests made using the tools in the portal.

This is available in an open beta for all customers across all plans! For more information check out our blog ↗︎ for this release.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue Operation list-vectors für Vectorize-Indizes

Mit der neuen Operation list-vectors lassen sich alle Vektor-IDs eines Vectorize-Index paginiert und snapshot-konsistent über Wrangler CLI und REST API auflisten.

You can now list all vector identifiers in a Vectorize index using the new list-vectors operation. This enables bulk operations, auditing, and data migration workflows through paginated requests that maintain snapshot consistency.

The operation is available via Wrangler CLI and REST API. Refer to the list-vectors best practices guide for detailed usage guidance.

Originalquelle(öffnet in neuem Tab)Problem melden

AI Gateway von Cloudflare

AI Gateway: BYOK jetzt mit Cloudflare Secrets Store

AI Gateway ist mit dem Cloudflare Secrets Store integriert, sodass sich KI-Anbieter-Schlüssel per BYOK zentral verwalten und im Request nur über eine Referenz statt im Klartext übergeben lassen, wobei Secrets mit dem neuen Scope ai_gateway im Dashboard, per wrangler oder API angelegt werden können.

Cloudflare Secrets Store is now integrated with AI Gateway, allowing you to store, manage, and deploy your AI provider keys in a secure and seamless configuration through Bring Your Own Key ↗︎. Instead of passing your AI provider keys directly in every request header, you can centrally manage each key with Secrets Store and deploy in your gateway configuration using only a reference, rather than passing the value in plain text.

You can now create a secret directly from your AI Gateway in the dashboard ↗︎ by navigating into your gateway -> Provider Keys -> Add.

Import repo or choose template

You can also create your secret with the newly available ai_gateway scope via wrangler ↗︎, the Secrets Store dashboard ↗︎, or the API ↗︎.

Then, pass the key in the request header using its Secrets Store reference:

curl -X POST https://gateway.ai.cloudflare.com/v1/<ACCOUNT_ID>/my-gateway/anthropic/v1/messages \
 --header 'cf-aig-authorization: ANTHROPIC_KEY_1 \
 --header 'anthropic-version: 2023-06-01' \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

DLP: Themenbasierte Erkennung für den Schutz von KI-Prompts

DLP erkennt und analysiert Prompts an Google Gemini, ChatGPT, Claude und Perplexity, klassifiziert sie nach Inhalts- und Absichtsthemen und bietet fünf neue vordefinierte Profile.

You now have access to a comprehensive suite of capabilities to secure your organization's use of generative AI. AI prompt protection introduces four key features that work together to provide deep visibility and granular control.

  1. Prompt Detection for AI Applications

DLP can now natively detect and inspect user prompts submitted to popular AI applications, including Google Gemini, ChatGPT, Claude, and Perplexity.

  1. Prompt Analysis and Topic Classification

Our DLP engine performs deep analysis on each prompt, applying topic classification. These topics are grouped into two evaluation categories:

  • Content: PII, Source Code, Credentials and Secrets, Financial Information, and Customer Data.

  • Intent: Jailbreak attempts, requests for malicious code, or attempts to extract PII.

To help you apply these topics quickly, we have also released five new predefined profiles (for example, AI Prompt: AI Security, AI Prompt: PII) that bundle these new topics.

DLP

  1. Granular Guardrails …

Originalquelle(öffnet in neuem Tab)Problem melden