Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

AI Gateway BYOK jetzt mit Cloudflare Secrets Store

Secrets Store ist in AI Gateway integriert, sodass KI-Provider-Schlüssel zentral verwaltet und in Anfragen nur noch per Referenz statt im Klartext übergeben werden können.

Cloudflare Secrets Store is now integrated with AI Gateway, allowing you to store, manage, and deploy your AI provider keys in a secure and seamless configuration through Bring Your Own Key ↗︎. Instead of passing your AI provider keys directly in every request header, you can centrally manage each key with Secrets Store and deploy in your gateway configuration using only a reference, rather than passing the value in plain text.

You can now create a secret directly from your AI Gateway in the dashboard ↗︎ by navigating into your gateway -> Provider Keys -> Add.

Import repo or choose template

You can also create your secret with the newly available ai_gateway scope via wrangler ↗︎, the Secrets Store dashboard ↗︎, or the API ↗︎.

Then, pass the key in the request header using its Secrets Store reference:

curl -X POST https://gateway.ai.cloudflare.com/v1/<ACCOUNT_ID>/my-gateway/anthropic/v1/messages \
 --header 'cf-aig-authorization: ANTHROPIC_KEY_1 \
 --header 'anthropic-version: 2023-06-01' \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Assets liefern JavaScript als text/javascript aus

JavaScript-Assets werden nun mit dem Content-Type text/javascript statt application/javascript ausgeliefert, was nach dem nächsten Deployment der Assets wirksam wird.

JavaScript asset responses have been updated to use the text/javascript Content-Type header instead of application/javascript. While both MIME types are widely supported by browsers, the HTML Living Standard explicitly recommends text/javascript as the preferred type going forward.

This change improves:

  • Standards alignment: Ensures consistency with the HTML spec and modern web platform guidance.
  • Interoperability: Some developer tools, validators, and proxies expect text/javascript and may warn or behave inconsistently with application/javascript.
  • Future-proofing: By following the spec-preferred MIME type, we reduce the risk of deprecation warnings or unexpected behavior in evolving browser environments.
  • Consistency: Most frameworks, CDNs, and hosting providers now default to text/javascript, so this change matches common ecosystem practice.

Because all major browsers accept both MIME types, this update is backwards compatible and should not cause breakage.

Users will see this change on the next deployment of their assets.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Assets liefern JavaScript jetzt als text/javascript aus

JavaScript-Assets werden mit dem Content-Type text/javascript statt application/javascript ausgeliefert, was laut Text abwärtskompatibel ist und bei der nächsten Bereitstellung der Assets wirksam wird.

JavaScript asset responses have been updated to use the text/javascript Content-Type header instead of application/javascript. While both MIME types are widely supported by browsers, the HTML Living Standard explicitly recommends text/javascript as the preferred type going forward.

This change improves:

  • Standards alignment: Ensures consistency with the HTML spec and modern web platform guidance.
  • Interoperability: Some developer tools, validators, and proxies expect text/javascript and may warn or behave inconsistently with application/javascript.
  • Future-proofing: By following the spec-preferred MIME type, we reduce the risk of deprecation warnings or unexpected behavior in evolving browser environments.
  • Consistency: Most frameworks, CDNs, and hosting providers now default to text/javascript, so this change matches common ecosystem practice.

Because all major browsers accept both MIME types, this update is backwards compatible and should not cause breakage.

Users will see this change on the next deployment of their assets.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

AI Gateway: BYOK mit Secrets Store

AI-Gateway ist jetzt mit Cloudflare Secrets Store integriert, sodass KI-Anbieter-Schlüssel zentral verwaltet und über Referenzen statt im Klartext bereitgestellt werden können.

Cloudflare Secrets Store is now integrated with AI Gateway, allowing you to store, manage, and deploy your AI provider keys in a secure and seamless configuration through Bring Your Own Key ↗︎. Instead of passing your AI provider keys directly in every request header, you can centrally manage each key with Secrets Store and deploy in your gateway configuration using only a reference, rather than passing the value in plain text.

You can now create a secret directly from your AI Gateway in the dashboard ↗︎ by navigating into your gateway -> Provider Keys -> Add.

Import repo or choose template

You can also create your secret with the newly available ai_gateway scope via wrangler ↗︎, the Secrets Store dashboard ↗︎, or the API ↗︎.

Then, pass the key in the request header using its Secrets Store reference:

curl -X POST https://gateway.ai.cloudflare.com/v1/<ACCOUNT_ID>/my-gateway/anthropic/v1/messages \
 --header 'cf-aig-authorization: ANTHROPIC_KEY_1 \
 --header 'anthropic-version: 2023-06-01' \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

AI Gateway unterstützt Bring Your Own Key

AI Gateway ist jetzt mit Cloudflare Secrets Store integriert; API-Schlüssel können zentral gespeichert und per Referenz in der Gateway-Konfiguration verwendet werden.

Cloudflare Secrets Store is now integrated with AI Gateway, allowing you to store, manage, and deploy your AI provider keys in a secure and seamless configuration through Bring Your Own Key ↗︎. Instead of passing your AI provider keys directly in every request header, you can centrally manage each key with Secrets Store and deploy in your gateway configuration using only a reference, rather than passing the value in plain text.

You can now create a secret directly from your AI Gateway in the dashboard ↗︎ by navigating into your gateway -> Provider Keys -> Add.

Import repo or choose template

You can also create your secret with the newly available ai_gateway scope via wrangler ↗︎, the Secrets Store dashboard ↗︎, or the API ↗︎.

Then, pass the key in the request header using its Secrets Store reference:

curl -X POST https://gateway.ai.cloudflare.com/v1/<ACCOUNT_ID>/my-gateway/anthropic/v1/messages \
 --header 'cf-aig-authorization: ANTHROPIC_KEY_1 \
 --header 'anthropic-version: 2023-06-01' \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update für Apache und Laravel

WAF-Regeln adressieren Remote Code Execution in Apache HTTP Server und Laravel; eine neue WordPress-Plugin-Regel ist zunächst deaktiviert.

This week's update

This week, critical vulnerabilities were disclosed that impact widely used open-source infrastructure, creating high-risk scenarios for code execution and operational disruption.

Key Findings

  • Apache HTTP Server – Code Execution (CVE-2024-38474): A flaw in Apache HTTP Server allows attackers to achieve remote code execution, enabling full compromise of affected servers. This vulnerability threatens the confidentiality, integrity, and availability of critical web services.

  • Laravel (CVE-2024-55661): A security flaw in Laravel introduces the potential for remote code execution under specific conditions. Exploitation could provide attackers with unauthorized access to application logic and sensitive backend data.

Impact

These vulnerabilities pose severe risks to enterprise environments and open-source ecosystems. Remote code execution enables attackers to gain deep system access, steal data, disrupt services, and establish persistent footholds for broader intrusions. Given the widespread deployment of Apache HTTP Server and Laravel in production systems, timely patching and mitigation are critical.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...28050359

100822_BETA

WordPress:Plugin:WPBookit - Remote Code Execution - CVE:CVE-2025-6058

N/A

Disabled …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers KV: Hybrid-Storage-Rollout senkt Latenz

Workers KV hat den Rollout einer hybriden Speicherarchitektur abgeschlossen, die laut Angaben die Leseverzögerung senkt, etwa p95 von ca. 150 ms auf ca. 50 ms in Europa, Asien, Nahost und Afrika.

Workers KV has completed rolling out performance improvements across all KV namespaces, providing a significant latency reduction on read operations for all KV users. This is due to architectural changes to KV's underlying storage infrastructure, which introduces a new metadata later and substantially improves redundancy.

Workers KV latency improvements showing P95 and P99 performance gains in Europe, Asia, Africa and Middle East regions as measured within KV's internal storage gateway worker.

Performance improvements

The new hybrid architecture delivers substantial latency reductions throughout Europe, Asia, Middle East, Africa regions. Over the past 2 weeks, we have observed the following:

  • p95 latency: Reduced from ~150ms to ~50ms (67% decrease)
  • p99 latency: Reduced from ~350ms to ~250ms (29% decrease)

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workflows jetzt in Python (Beta)

Workflows lassen sich nun in Python mit automatischen Wiederholungen, Zustandsspeicherung und DAG-Abhängigkeiten über den depends-Parameter bauen (Beta).

You can now build Workflows using Python. With Python Workflows, you get automatic retries, state persistence, and the ability to run multi-step operations that can span minutes, hours, or weeks using Python’s familiar syntax and the Python Workers runtime.

Python Workflows use the same step-based execution model as JavaScript Workflows, but with Python syntax and access to Python’s ecosystem. Python Workflows also enable DAG (Directed Acyclic Graph) workflows, where you can define complex dependencies between steps using the depends parameter.

Here’s a simple example:

from workers import Response, WorkflowEntrypoint

class PythonWorkflowStarter(WorkflowEntrypoint):
    async def run(self, event, step):
        @step.do("my first step")
        async def my_first_step():
            # do some work
            return "Hello Python!"

        await my_first_step()

        await step.sleep("my-sleep-step", "10 seconds")

        @step.do("my second step")
        async def my_second_step():
            # do some more work
            return "Hello again!"

        await my_second_step()

class Default(WorkerEntrypoint):
    async def fetch(self, request):
        await self.env.MY_WORKFLOW.create()
        return Response("Hello Workflow creation!")

Note …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update mit neuen deaktivierten Regeln

Elf neue WAF-Regeln zu Command Injection, XSS, SQLi und mehr wurden als Beta-Versionen hinzugefügt, sind aber standardmäßig deaktiviert.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...5fcca5c8

100850

Command Injection - Generic 2

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...744305c4

100851

Remote Code Execution - Java Deserialization

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...2b083459

100852

Command Injection - Generic 3

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...efb7e5b9

100853

Remote Code Execution - Common Bash Bypass Beta

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...78513ad7

100854

XSS - Generic JavaScript

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...e9a5daac

100855

Command Injection - Generic 4

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...480f6093

100856

PHP Object Injection

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...d4ae0a33

100857

Generic - Parameter Fuzzing

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...1121ee45

100858

Code Injection - Generic 4

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...20de01e3

100859

SQLi - UNION - 2

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...c0177e21

100860

Command Injection - Generic 5

N/A

Disabled

This is a New Detection

Cloudflare Managed Ruleset

...85f4d7b3

100861

Command Execution - Generic

N/A

Disabled …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Audit Logs v2 für Logpush verfügbar

Der Audit Logs v2-Datensatz ist jetzt über Logpush verfügbar; Cloudflare empfiehlt, einen neuen Logpush-Job für das Dataset zu erstellen.

Audit Logs v2 dataset is now available via Logpush.

This expands on earlier releases of Audit Logs v2 in the API and Dashboard UI.

We recommend creating a new Logpush job for the Audit Logs v2 dataset.

Timelines for General Availability (GA) of Audit Logs v2 and the retirement of Audit Logs v1 will be shared in upcoming updates.

For more details on Audit Logs v2, refer to the Audit Logs documentation ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Dedizierte Egress-IPs für Logpush

Logpush kann Logs jetzt über feste, dedizierte Egress-IPs liefern, indem eine Cloudflare-Zone mit Aegis IP als Proxy genutzt wird.

Cloudflare Logpush can now deliver logs from using fixed, dedicated egress IPs. By routing Logpush traffic through a Cloudflare zone enabled with Aegis IP, your log destination only needs to allow Aegis IPs making setup more secure.

Highlights:

  • Fixed egress IPs ensure your destination only accepts traffic from known addresses.
  • Works with any supported Logpush destination.
  • Recommended to use a dedicated zone as a proxy for easier management.

To get started, work with your Cloudflare account team to provision Aegis IPs, then configure your Logpush job to deliver logs through the proxy zone. For full setup instructions, refer to the Logpush documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway: BYOIP für dedizierte Egress-IPs verfügbar

Enterprise-Gateway-Nutzer können eigene IPv4- oder IPv6-Präfixe per BYOIP als dedizierte Egress-IPs einbinden und in Egress-Richtlinien auswählen.

Enterprise Gateway users can now use Bring Your Own IP (BYOIP) for dedicated egress IPs.

Admins can now onboard and use their own IPv4 or IPv6 prefixes to egress traffic from Cloudflare, delivering greater control, flexibility, and compliance for network traffic.

Get started by following the BYOIP onboarding process. Once your IPs are onboarded, go to Gateway > Egress policies and select or create an egress policy. In Select an egress IP, choose Use dedicated egress IPs (Cloudflare or BYOIP), then select your BYOIP address from the dropdown menu.

Screenshot of a dropdown menu adding a BYOIP IPv4 address as a dedicated egress IP in a Gateway egress policy

For more information, refer to BYOIP for dedicated egress IPs.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neue getByName()-API für Durable Objects

Mit der neuen Methode getByName erhält man einen Durable-Object-Stub direkt über den Namen, ohne zuvor Namen in IDs umzuwandeln.

You can now create a client (a Durable Object stub) to a Durable Object with the new getByName method, removing the need to convert Durable Object names to IDs and then create a stub.

// Before: (1) translate name to ID then (2) get a client 
const objectId = env.MY_DURABLE_OBJECT.idFromName("foo"); // or .newUniqueId()
const stub = env.MY_DURABLE_OBJECT.get(objectId); 

// Now: retrieve client to Durable Object directly via its name 
const stub = env.MY_DURABLE_OBJECT.getByName("foo");

// Use client to send request to the remote Durable Object
const rpcResponse = await stub.sayHello();

Each Durable Object has a globally-unique name, which allows you to send requests to a specific object from anywhere in the world. Thus, a Durable Object can be used to coordinate between multiple clients who need to work together. You can have billions of Durable Objects, providing isolation between application tenants.

To learn more, visit the Durable Objects API Documentation or the getting started guide.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Events von Cloudflare-Diensten über Queues abonnieren

Events anderer Cloudflare-Dienste wie Workers KV, Workers AI oder R2 können nun abonniert und über Queues mit Workers oder per HTTP-Pull verarbeitet werden.

You can now subscribe to events from other Cloudflare services (for example, Workers KV, Workers AI, Workers) and consume those events via Queues, allowing you to build custom workflows, integrations, and logic in response to account activity.

Event subscriptions architecture

Event subscriptions allow you to receive messages when events occur across your Cloudflare account. Cloudflare products can publish structured events to a queue, which you can then consume with Workers or pull via HTTP from anywhere.

To create a subscription, use the dashboard or Wrangler:

npx wrangler queues subscription create my-queue --source r2 --events bucket.created

An event is a structured record of something happening in your Cloudflare account – like a Workers AI batch request being queued, a Worker build completing, or an R2 bucket being created. Events follow a consistent structure:

Example R2 bucket created eventjson

{ …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Verbesserter Wrangler-Fehlerbildschirm

Der Fehlerbildschirm von Wrangler hat ein neues Design mit hellem und dunklem Theme, zuverlässigere Source-Map-Auflösung und bessere Anzeige von Fehlerursachen.

Wrangler's error screen has received several improvements to enhance your debugging experience!

The error screen now features a refreshed design thanks to youch ↗︎, with support for both light and dark themes, improved source map resolution logic that handles missing source files more reliably, and better error cause display.

Before

After (Light)

After (Dark)

Old error screen

New light theme error screen

New dark theme error screen

Try it out now with npx wrangler@latest dev in your Workers project.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update für SonicWall und Ms-Swift

WAF-Regeln für SonicWall SMA Path Traversal/Command Injection und Ms-Swift YAML-Deserialisierung (CVE-2025-32819, -50460) wurden ergänzt.

This week's update

This week, a series of critical vulnerabilities were discovered impacting core enterprise and open-source infrastructure. These flaws present a range of risks, providing attackers with distinct pathways for remote code execution, methods to breach internal network boundaries, and opportunities for critical data exposure and operational disruption.

Key Findings

  • SonicWall SMA (CVE-2025-32819, CVE-2025-32820, CVE-2025-32821): A remote authenticated attacker with SSLVPN user privileges can bypass path traversal protections. These vulnerabilities enable a attacker to bypass security checks to read, modify, or delete arbitrary files. An attacker with administrative privileges can escalate this further, using a command injection flaw to upload malicious files, which could ultimately force the appliance to reboot to its factory default settings.

  • Ms-Swift Project (CVE-2025-50460): An unsafe deserialization vulnerability exists in the Ms-Swift project's handling of YAML configuration files. If an attacker can control the content of a configuration file passed to the application, they can embed a malicious payload that will execute arbitrary code and it can be executed during deserialization. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

node:fs und Web File System API in Workers verfügbar

Workers bieten nun Implementierungen von node:fs und der Web File System API mit einem virtuellen, pro Anfrage isolierten und flüchtigen Dateisystem, standardmäßig mit nodejs_compat ab Compatibility Date 2025-09-01.

Implementations of the node:fs module ↗︎ and the Web File System API ↗︎ are now available in Workers.

Using the node:fs module

The node:fs module provides access to a virtual file system in Workers. You can use it to read and write files, create directories, and perform other file system operations.

The virtual file system is ephemeral with each individual request havig its own isolated temporary file space. Files written to the file system will not persist across requests and will not be shared across requests or across different Workers.

Workers running with the nodejs_compat compatibility flag will have access to the node:fs module by default when the compatibility date is set to 2025-09-01 or later. Support for the API can also be enabled using the enable_nodejs_fs_module compatibility flag together with the nodejs_compat flag. The node:fs module can be disabled using the disable_nodejs_fs_module compatibility flag.

import fs from "node:fs";

const config = JSON.parse(fs.readFileSync("/bundle/config.json", "utf-8"));

export default {
	async fetch(request) {
		return new Response(`Config value: ${config.value}`);
	},
};

There are a number of initial limitations to the node:fs implementation:

  • The glob APIs (e.g. fs.globSync(...)) are not implemented. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Static Assets: Doppelte Schrägstriche in Redirects korrigiert

Ein Fehler wurde behoben, bei dem Pfade mit doppelten Schrägstrichen in _redirects-Regeln fälschlich als externe URLs interpretiert wurden, und sie werden nun als lokale Pfade aufgelöst.

Static Assets: Fixed a bug in how redirect rules ↗︎ defined in your Worker's _redirects file are processed.

If you're serving Static Assets with a _redirects file containing a rule like /ja/* /:splat, paths with double slashes were previously misinterpreted as external URLs. For example, visiting /ja//example.com would incorrectly redirect to https://example.com instead of /example.com on your domain. This has been fixed and double slashes now correctly resolve as local paths. Note: Cloudflare Pages was not affected by this issue.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

Load Balancing: Traffic nach AS-Nummer steuern

Load-Balancing-Custom-Rules können nun die autonome Systemnummer (ASN) einer Anfrage verwenden, um Traffic präziser nach Netzwerkquelle zu steuern.

You can now create more granular, network-aware Custom Rules in Cloudflare Load Balancing using the Autonomous System Number (ASN) of an incoming request.

This allows you to steer traffic with greater precision based on the network source of a request. For example, you can route traffic from specific Internet Service Providers (ISPs) or enterprise customers to dedicated infrastructure, optimize performance, or enforce compliance by directing certain networks to preferred data centers.

Create a Load Balancing Custom Rule using AS Num

To get started, create a Custom Rule ↗︎ in your Load Balancer and select AS Num from the Field dropdown.

Originalquelle(öffnet in neuem Tab)Problem melden