Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Agents SDK: MCP Elicitation, http-streamable, Task Queues und E-Mail

Das @cloudflare/agents SDK unterstützt MCP Elicitation für Nutzereingaben während der Tool-Ausführung sowie HTTP streamable transport für MCP, der gegenüber SSE empfohlen wird, und bringt weitere Neuerungen wie Task Queues und E-Mail-Integration.

The latest releases of @cloudflare/agents ↗︎ brings major improvements to MCP transport protocols support and agents connectivity. Key updates include:

MCP elicitation support

MCP servers can now request user input during tool execution, enabling interactive workflows like confirmations, forms, and multi-step processes. This feature uses durable storage to preserve elicitation state even during agent hibernation, ensuring seamless user interactions across agent lifecycle events.

// Request user confirmation via elicitation
const confirmation = await this.elicitInput({
	message: `Are you sure you want to increment the counter by ${amount}?`,
	requestedSchema: {
		type: "object",
		properties: {
			confirmed: {
				type: "boolean",
				title: "Confirm increment",
				description: "Check to confirm the increment",
			},
		},
		required: ["confirmed"],
	},
});

Check out our demo ↗︎ to see elicitation in action.

HTTP streamable transport for MCP

MCP now supports HTTP streamable transport which is recommended over SSE. This transport type offers:

  • Better performance: More efficient data streaming and reduced overhead …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Sandbox SDK: Streaming, Code Interpreter, Git und Prozesssteuerung

Das @cloudflare/sandbox SDK bietet nun Live-Streaming der Ausgabe, persistente Code Interpreter für Python und JavaScript, Dateisystemzugriff, Git-Operationen, Steuerung von Hintergrundprozessen und öffentliche URLs für laufende Dienste.

We’ve shipped a major release for the @cloudflare/sandbox ↗︎ SDK, turning it into a full-featured, container-based execution platform that runs securely on Cloudflare Workers.

This update adds live streaming of output, persistent Python and JavaScript code interpreters with rich output support (charts, tables, HTML, JSON), file system access, Git operations, full background process control, and the ability to expose running services via public URLs.

This makes it ideal for building AI agents, CI runners, cloud REPLs, data analysis pipelines, or full developer tools — all without managing infrastructure.

Code interpreter (Python, JS, TS)

Create persistent code contexts with support for rich visual + structured outputs.

createCodeContext(options)

Creates a new code execution context with persistent state.

// Create a Python context
const pythonCtx = await sandbox.createCodeContext({ language: "python" });

// Create a JavaScript context
const jsCtx = await sandbox.createCodeContext({ language: "javascript" });

Options:

  • language: Programming language ('python' | 'javascript' | 'typescript')
  • cwd: Working directory (default: /workspace)
  • envVars: Environment variables for the context

runCode(code, options)

Executes code with optional streaming callbacks.

// Simple execution …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

OpenAI Open Models auf Workers AI verfügbar

Die Modelle @cf/openai/gpt-oss-120b und @cf/openai/gpt-oss-20b sind auf Workers AI verfügbar, mit Unterstützung für die Responses API und Code Interpreter, Web Search soll folgen.

We're thrilled to be a Day 0 partner with OpenAI ↗︎ to bring their latest open models ↗︎ to Workers AI, including support for Responses API, Code Interpreter, and Web Search (coming soon).

Get started with the new models at @cf/openai/gpt-oss-120b and @cf/openai/gpt-oss-20b. Check out the blog ↗︎ for more details about the new models, and the gpt-oss-120b and gpt-oss-20b model pages for more information about pricing and context windows.

Responses API

If you call the model through:

  • Workers Binding, it will accept/return Responses API – env.AI.run(“@cf/openai/gpt-oss-120b”)
  • REST API on /run endpoint, it will accept/return Responses API – https://api.cloudflare.com/client/v4/accounts/<account_id>/ai/run/@cf/openai/gpt-oss-120b
  • REST API on new /responses endpoint, it will accept/return Responses API – https://api.cloudflare.com/client/v4/accounts/<account_id>/ai/v1/responses
  • REST API for OpenAI Compatible endpoint, it will return Chat Completions (coming soon) – https://api.cloudflare.com/client/v4/accounts/<account_id>/ai/v1/chat/completions
curl https://api.cloudflare.com/client/v4/accounts/<account_id>/ai/v1/responses \ …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Mehr Speicherplatz für Workers Builds: 20 GB

Der Festplattenspeicher für Workers Builds in der Open Beta steigt für Free- und Paid-Pläne von 8 GB auf 20 GB, die übrigen Build-Limits bleiben unverändert.

As part of the ongoing open beta for Workers Builds, we’ve increased the available disk space for builds from 8 GB to 20 GB for both Free and Paid plans.

This provides more space for larger projects, dependencies, and build artifacts while improving overall build reliability.

Metric

Free Plan

Paid Plans

Disk Space

20 GB

20 GB

All other build limits — including CPU, memory, build minutes, and timeout remain unchanged.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update vom 04.08.2025

Die WAF-Regeln wurden um Schutz für Schwachstellen in Sitecore, Grafana, LaRecipe, CentOS WebPanel und WordPress erweitert.

This week's highlight focuses on a series of significant vulnerabilities identified across widely adopted web platforms, from enterprise-grade CMS to essential backend administration tools. The findings reveal multiple vectors for attack, including critical flaws that allow for full server compromise and others that enable targeted attacks against users.

Key Findings

  • Sitecore (CVE-2025-34509, CVE-2025-34510, CVE-2025-34511): A hardcoded credential allows remote attackers to access administrative APIs. Once authenticated, they can exploit an additional vulnerability to upload arbitrary files, leading to remote code execution.

  • Grafana (CVE-2025-4123): A cross-site scripting (XSS) vulnerability allows an attacker to redirect users to a malicious website, which can then execute arbitrary JavaScript in the victim's browser.

  • LaRecipe (CVE-2025-53833): Through Server-Side Template Injection, attackers can execute arbitrary commands on the server, potentially access sensitive environment variables, and escalate access depending on server configuration.

  • CentOS WebPanel (CVE-2025-48703): A command injection vulnerability could allow a remote attacker to execute arbitrary commands on the server.

  • WordPress (CVE-2023-5561): This vulnerability allows unauthenticated attackers to determine the email addresses of users who have published public posts on an affected website. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Lokale Entwicklung mit Containers im Cloudflare Vite plugin

Containers lassen sich jetzt auch mit dem Cloudflare Vite plugin lokal neben dem Worker konfigurieren und ausführen, zuvor ging das nur mit Wrangler.

You can now configure and run Containers alongside your Worker during local development when using the Cloudflare Vite plugin. Previously, you could only develop locally when using Wrangler as your local development server.

Configuration

You can simply configure your Worker and your Container(s) in your Wrangler configuration file:

{
  "name": "container-starter",
  "main": "src/index.js",
  "containers": [
    {
      "class_name": "MyContainer",
      "image": "./Dockerfile",
      "instances": 5
    }
  ],
  "durable_objects": {
    "bindings": [
      {
        "class_name": "MyContainer",
        "name": "MY_CONTAINER"
      }
    ]
  },
  "migrations": [
    {
      "new_sqlite_classes": [
        "MyContainer"
      ],
      "tag": "v1"
    }
  ],
}
name = "container-starter"
main = "src/index.js"

[[containers]]
class_name = "MyContainer"
image = "./Dockerfile"
instances = 5

[[durable_objects.bindings]]
class_name = "MyContainer"
name = "MY_CONTAINER"

[[migrations]]
new_sqlite_classes = [ "MyContainer" ]
tag = "v1"

Worker Code

Once your Worker and Containers are configured, you can access the Container instances from your Worker code:

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform-Provider v5.8.2 verfügbar

Der Terraform v5-Provider in Version 5.8.2 stabilisiert mehrere Ressourcen, behebt Drift-Probleme und verbessert die Handhabung von bindings.

Earlier this year, we announced the launch of the new Terraform v5 Provider. We are aware of the high number of issues ↗︎ reported by the Cloudflare community related to the v5 release. We have committed to releasing improvements on a 2 week cadeance to ensure it's stability and reliability. We have also pivoted from an issue-to-issue approach to a resource-per-resource approach - we will be focusing on specific resources for every release, stabilizing the release and closing all associated bugs with that resource before moving onto resolving migration issues.

Thank you for continuing to raise issues. We triage them weekly and they help make our products stronger.

Changes

  • Resources stabilized:
    • cloudflare_custom_pages
    • cloudflare_page_rule
    • cloudflare_dns_record
    • cloudflare_argo_tiered_caching
  • Addressed chronic drift issues in cloudflare_logpush_job, cloudflare_zero_trust_dns_location, cloudflare_ruleset & cloudflare_api_token
  • cloudflare_zone_subscription returns expected values rate_plan.id from former versions
  • cloudflare_workers_script can now successfully be destroyed with bindings & migration for Durable Objects now recorded in tfstate
  • Ability to configure add_headers under cloudflare_zero_trust_gateway_policy
  • Other bug fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Cloudflare WAN: Terraform-V5-Unterstützung für Tunnel und Routen

Die Terraform-Provider-Ressourcen für Cloudflare WAN Tunnel und Routen unterstützen nun Terraform Provider Version 5.

The Cloudflare Terraform provider resources for Cloudflare WAN tunnels and routes now support Terraform provider version 5. Customers using infrastructure-as-code workflows can manage their tunnel and route configuration with the latest provider version.

For more information, refer to the Cloudflare Terraform provider documentation ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Magic Transit und Magic WAN: Health-Check-Daten mit CMB EU kompatibel

Kunden mit aktiviertem CMB EU können nun GRE-, IPsec- und CNI-Health-Check- sowie Traffic-Volumen-Daten im Dashboard und per API abrufen, da die GraphQL-Endpunkte magicTransitTunnelHealthChecksAdaptiveGroups und magicTransitTunnelTrafficAdaptiveGroups kompatibel sind.

Today, we are excited to announce that all Magic Transit and Magic WAN customers with CMB EU (Customer Metadata Boundary - Europe) enabled in their account will be able to access GRE, IPsec, and CNI health check and traffic volume data in the Cloudflare dashboard and via API.

This ensures that all Magic Transit and Magic WAN customers with CMB EU enabled will be able to access all Magic Transit and Magic WAN features.

Specifically, these two GraphQL endpoints are now compatible with CMB EU:

  • magicTransitTunnelHealthChecksAdaptiveGroups
  • magicTransitTunnelTrafficAdaptiveGroups

Originalquelle(öffnet in neuem Tab)Problem melden

Network Security von Cloudflare

Health-Check-Daten kompatibel mit CMB EU

Magic Transit- und Magic WAN-Kunden mit CMB EU können jetzt über zwei GraphQL-Endpunkte auf Health-Check- und Verkehrsdaten zugreifen.

Today, we are excited to announce that all Magic Transit and Magic WAN customers with CMB EU (Customer Metadata Boundary - Europe) enabled in their account will be able to access GRE, IPsec, and CNI health check and traffic volume data in the Cloudflare dashboard and via API.

This ensures that all Magic Transit and Magic WAN customers with CMB EU enabled will be able to access all Magic Transit and Magic WAN features.

Specifically, these two GraphQL endpoints are now compatible with CMB EU:

  • magicTransitTunnelHealthChecksAdaptiveGroups
  • magicTransitTunnelTrafficAdaptiveGroups

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Deploy-Buttons unterstützen Variablen und Secrets

Deploy-to-Cloudflare-Buttons unterstützen jetzt Worker-Umgebungsvariablen, Secrets und Secrets-Store-Secrets aus der Wrangler-Konfiguration.

Any template which uses Worker environment variables, secrets, or Secrets Store secrets can now be deployed using a Deploy to Cloudflare button.

Define environment variables and secrets store bindings in your Wrangler configuration file as normal:

{
  "name": "my-worker",
  "main": "./src/index.ts",
	// Set this to today's date
	"compatibility_date": "2026-10-11",
  "vars": {
    "API_HOST": "https://example.com",
  },
	"secrets_store_secrets": [
		{
			"binding": "API_KEY",
			"store_id": "demo",
			"secret_name": "api-key"
		}
	]
}
name = "my-worker"
main = "./src/index.ts"
# Set this to today's date
compatibility_date = "2026-10-11"

[vars]
API_HOST = "https://example.com"

[[secrets_store_secrets]]
binding = "API_KEY"
store_id = "demo"
secret_name = "api-key"

Add secrets to a .dev.vars.example or .env.example file:

.dev.vars.exampleini

COOKIE_SIGNING_KEY=my-secret # comment

And optionally, you can add a description for these bindings in your template's package.json to help users understand how to configure each value:

package.jsonjson

{
	"name": "my-worker",
	"private": true,
	"cloudflare": {
		"bindings": {
			"API_KEY": { …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Deploy-Buttons unterstützen jetzt Worker-Umgebungsvariablen und Secrets

Vorlagen mit Worker-Umgebungsvariablen, Secrets und Secrets-Store-Secrets können jetzt über den „Deploy to Cloudflare“-Button bereitgestellt werden.

Any template which uses Worker environment variables, secrets, or Secrets Store secrets can now be deployed using a Deploy to Cloudflare button.

Define environment variables and secrets store bindings in your Wrangler configuration file as normal:

{
  "name": "my-worker",
  "main": "./src/index.ts",
	// Set this to today's date
	"compatibility_date": "2026-10-11",
  "vars": {
    "API_HOST": "https://example.com",
  },
	"secrets_store_secrets": [
		{
			"binding": "API_KEY",
			"store_id": "demo",
			"secret_name": "api-key"
		}
	]
}
name = "my-worker"
main = "./src/index.ts"
# Set this to today's date
compatibility_date = "2026-10-11"

[vars]
API_HOST = "https://example.com"

[[secrets_store_secrets]]
binding = "API_KEY"
store_id = "demo"
secret_name = "api-key"

Add secrets to a .dev.vars.example or .env.example file:

.dev.vars.exampleini

COOKIE_SIGNING_KEY=my-secret # comment

And optionally, you can add a description for these bindings in your template's package.json to help users understand how to configure each value:

package.jsonjson

{
	"name": "my-worker",
	"private": true,
	"cloudflare": {
		"bindings": {
			"API_KEY": { …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Audit Logs v2 UI als Beta verfügbar

Die neue Audit Logs v2-Benutzeroberfläche ist für alle Kunden in der Beta verfügbar und bietet erweiterte Filteroptionen, eine Detail-Sidebar und JSON-Ansicht.

The Audit Logs v2 UI is now available to all Cloudflare customers in Beta. This release builds on the public Beta of the Audit Logs v2 API and introduces a redesigned user interface with powerful new capabilities to make it easier to investigate account activity.

Enabling the new UI

To try the new user interface, go to Manage Account > Audit Logs. The previous version of Audit Logs remains available and can be re-enabled at any time using the Switch back to old Audit Logs link in the banner at the top of the page.

New Features:

  • Advanced Filtering: Filter logs by actor, resource, method, and more for faster insights.
  • On-hover filter controls: Easily include or exclude values in queries by hovering over fields within a log entry.
  • Detailed Log Sidebar: View rich context for each log entry without leaving the main view.
  • JSON Log View: Inspect the raw log data in a structured JSON format.
  • Custom Time Ranges: Define your own time windows to view historical activity.
  • Infinite Scroll: Seamlessly browse logs without clicking through pages.

Audit Logs v2 new UI …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway: Neue Kategorie „Scam“ unter Security Threats

Unter den Security Threats gibt es die neue Kategorie Scam (ID 191) für betrügerische Websites und Maschen, mit der entsprechende Domains markiert werden.

We have introduced a new Security Threat category called Scam. Relevant domains are marked with the Scam category. Scam typically refers to fraudulent websites and schemes designed to trick victims into giving away money or personal information.

New category added

Parent ID

Parent Name

Category ID

Category Name

21

Security Threats

191

Scam

Refer to Gateway domain categories to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Preise für Browser Rendering API: $0.09 pro Browser-Stunde

Ab dem 20. August 2025 berechnet Cloudflare Browser Rendering mit Free-Kontingent und Pay-as-you-go-Modell, wobei die REST API nach Dauer und Browser Sessions zusätzlich nach Parallelität abgerechnet werden.

We’ve launched pricing for Browser Rendering, including a free tier and a pay-as-you-go model that scales with your needs. Starting August 20, 2025, Cloudflare will begin billing for Browser Rendering.

There are two ways to use Browser Rendering. Depending on the method you use, here’s how billing will work:

  • REST API: Charged for Duration only ($/browser hour)
  • Browser Sessions: Charged for both Duration and Concurrency ($/browser hour and # of concurrent browsers)

Included usage and pricing by plan

Plan

Included duration

Included concurrency

Price (beyond included)

Workers Free

10 minutes per day

3 concurrent browsers

N/A

Workers Paid

10 hours per month

10 concurrent browsers (averaged monthly)

1. REST API: $0.09 per additional browser hour
2. Workers Bindings: $0.09 per additional browser hour
$2.00 per additional concurrent browser

What you need to know:

  • Workers Free Plan: 10 minutes of browser usage per day with 3 concurrent browsers at no charge.
  • Workers Paid Plan: 10 hours of browser usage per month with 10 concurrent browsers (averaged monthly) at no charge. Additional usage is charged as shown above. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update vom 28.07.2025

Die WAF-Regeln wurden um Schutz für Schwachstellen in Fortinet FortiWeb, Apache Tomcat und MongoDB ergänzt.

This week’s update spotlights several vulnerabilities across Apache Tomcat, MongoDB, and Fortinet FortiWeb. Several flaws related with a memory leak in Apache Tomcat can lead to a denial-of-service attack. Additionally, a code injection flaw in MongoDB's Mongoose library allows attackers to bypass security controls to access restricted data.

Key Findings

  • Fortinet FortiWeb (CVE-2025-25257): An improper neutralization of special elements used in a SQL command vulnerability in Fortinet FortiWeb versions allows an unauthenticated attacker to execute unauthorized SQL code or commands.

  • Apache Tomcat (CVE-2025-31650): A improper Input Validation vulnerability in Apache Tomcat that could create memory leak when incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request.

  • MongoDB (CVE-2024-53900, CVE:CVE-2025-23061): Improper use of $where in match and a nested $where filter with a populate() match in Mongoose can lead to search injection.

Impact …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway: HTTP-Filterung auf allen Ports in offener Beta

Gateway kann HTTP-Filterung nun auf alle proxied HTTP-Anfragen und nicht nur auf die Ports 80 und 443 anwenden, aktivierbar über Settings > Network > Firewall mit „Inspect on all ports“.

Gateway can now apply HTTP filtering to all proxied HTTP requests, not just traffic on standard HTTP (80) and HTTPS (443) ports. This means all requests can now be filtered by A/V scanning, file sandboxing, Data Loss Prevention (DLP), and more.

You can turn this setting on by going to Settings > Network > Firewall and choosing Inspect on all ports.

HTTP Inspection on all ports setting

To learn more, refer to Inspect on all ports (Beta).

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Gateway: Google Bard durch Gemini ersetzt

Die Anwendung Google Bard (ID 1198) wurde entfernt und durch Gemini (ID 1340) ersetzt, sodass bestehende Gateway-Policies mit Bard nicht mehr funktionieren und auf Gemini umgestellt werden sollten.

The Google Bard application (ID: 1198) has been deprecated and fully removed from the system. It has been replaced by the Gemini application (ID: 1340). Any existing Gateway policies that reference the old Google Bard application will no longer function. To ensure your policies continue to work as intended, you should update them to use the new Gemini application. We recommend replacing all instances of the deprecated Bard application with the new Gemini application in your Gateway policies. For more information about application policies, please see the Cloudflare Gateway documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Browser Rendering unterstützt lokale Entwicklung

Browser Rendering lässt sich nun lokal mit npx wrangler dev ausführen, wobei ein Browser auf dem eigenen Rechner gestartet wird, sodass Tests ohne Deployment und Nutzungskosten möglich sind.

You can now run your Browser Rendering locally using npx wrangler dev, which spins up a browser directly on your machine before deploying to Cloudflare's global network. By running tests locally, you can quickly develop, debug, and test changes without needing to deploy or worry about usage costs.

Get started with this example guide that shows how to use Cloudflare's fork of Puppeteer (you can also use Playwright) to take screenshots of webpages and store the results in Workers KV.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Preview-Deployments pro Branch für Cloudflare Workers

Bei Anbindung eines Workers an ein GitHub- oder GitLab-Repository erhält jeder Branch eine stabile Preview-URL, die als Kommentar im Pull Request erscheint und stets auf den neuesten Stand des Branches zeigt.

Now, when you connect your Cloudflare Worker to a git repository on GitHub or GitLab, each branch of your repository has its own stable preview URL, that you can use to preview code changes before merging the pull request and deploying to production.

This works the same way that Cloudflare Pages does — every time you create a pull request, you'll automatically get a shareable preview link where you can see your changes running, without affecting production. The link stays the same, even as you add commits to the same branch. These preview URLs are named after your branch and are posted as a comment to each pull request. The URL stays the same with every commit and always points to the latest version of that branch.

PR comment preview

Preview URL types

Each comment includes two preview URLs as shown above:

  • Commit Preview URL: Unique to the specific version/commit (e.g., <version-prefix>-<worker-name>.<subdomain>.workers.dev)
  • Branch Preview URL: A stable alias based on the branch name (e.g., <branch-name>-<worker-name>.<subdomain>.workers.dev)

How it works

When you create a pull request:

  • A preview alias is automatically created based on the Git branch name (e.g., <branch-name> becomes <branch-name>-<worker-name>.<subdomain>.workers.dev) …

Originalquelle(öffnet in neuem Tab)Problem melden