Zum Inhalt springen

Sicherheit und Anmeldung: Release Notes

Schutz vor Angriffen, Schwachstellen-Scanner, Anmeldung und Zugriffsverwaltung. 8 Hersteller, 2.066 Einträge.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

AI Search allgemein verfügbar, Abrechnung ab 1. November 2026

AI Search ist allgemein verfügbar, die nutzungsbasierte Abrechnung beginnt am 1. November 2026, neue Instanzen nutzen standardmäßig Hybrid Search, Workers-AI-Embeddings und Reranking sind im Preis enthalten und multimodale Embedding-Modelle mit Bildunterstützung kommen hinzu.

Refer to Limits & pricing for rates and included usage.

Hybrid search is on by default

New AI Search instances use hybrid search by default. Hybrid search combines semantic vector retrieval with full-text matching. You can choose a different index method when you create an instance.

Refer to Hybrid search for details.

Workers AI embeddings and reranking are included

Workers AI embedding and reranking calls made by AI Search are included in AI Search pricing. These calls no longer appear on your Workers AI bill or in your AI Gateway logs. Generation, query rewriting, and external providers continue to use your account and gateway.

Refer to Limits & pricing for details.

Multimodal model and image support

AI Search supports the @cf/qwen/qwen3-vl-embedding-2b and google-ai-studio/gemini-embedding-2 multimodal embedding models. Search and chat requests can include images through the REST API and public endpoint.

Refer to Supported models for the full list of embedding models.

OCR availability and increased file limits …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.8.2100.0 (GA)

Das GA-Release des Cloudflare One Client für macOS blockiert Verkehr zu Split-Tunnel-Ausnahmen beim Verbinden nicht mehr kurzzeitig, unterstützt Nicht-RFC-1918-Netze bei uneingeschränkter LAN-Einbindung, verbindet schneller bei geringerem Speicherverbrauch und bringt weitere Verbesserungen bei Reauthentifizierung, MTU- und DNS-Handling sowie eine neue MDM-Einstellung für IPv4-Präferenz im Proxy-Modus.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release includes the following highlights:

  • Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across reconnects.
  • Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Faster connects and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.

Additional changes and improvements

  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Individual DNS-over-HTTPS queries now time out instead of hanging when the upstream server stops responding.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • Added an MDM setting to prefer IPv4 when resolving hostnames in proxy mode. The setting is off by default. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.8.2100.0 (GA)

Das GA-Release des Cloudflare One Client für Windows blockiert Verkehr zu Split-Tunnel-Ausnahmen beim Verbinden nicht mehr kurzzeitig, unterstützt Nicht-RFC-1918-Netze bei uneingeschränkter LAN-Einbindung, geht besser mit sehr großen Hosts-Dateien um, stellt Tunnel schneller wieder her und startet den Client-Dienst bei Systementsperrung per geplanter Aufgabe automatisch, falls er nicht läuft.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release includes the following highlights:

  • Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across tunnel reconnections.
  • Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved connection reliability on devices with very large hosts files. The client now detects a large hosts file, allows more time for its initial DNS check, and shows a banner letting the user know that connecting may take longer.
  • Faster tunnel reconnections and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.
  • A service recovery mechanism, backed by a Windows scheduled task, now starts the client service on system unlock if it is not already running. This is enabled by default.

Additional changes and improvements

  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.8.2100.0 (GA)

Das GA-Release des Cloudflare One Client für Linux blockiert Verkehr zu Split-Tunnel-Ausnahmen beim Verbinden nicht mehr kurzzeitig, unterstützt Nicht-RFC-1918-Netze bei uneingeschränkter LAN-Einbindung, stellt Tunnel schneller wieder her, bietet eine neue MDM-Einstellung für IPv4-Präferenz im Proxy-Modus und verbessert Reauthentifizierung, MTU-Handling und DNS-Zuverlässigkeit.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release includes the following highlights:

  • Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across reconnects.
  • Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Faster tunnel reconnections and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.
  • Added an MDM setting to prefer IPv4 when resolving hostnames in proxy mode. The setting is off by default.

Additional changes and improvements

  • Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
  • Improved client reaction to the current network lowering its MTU.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Individual DNS-over-HTTPS queries now time out instead of hanging when the upstream server stops responding.
  • Improved API reliability by retrying requests dropped when reusing pooled connections. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Organizations ist allgemein verfügbar

Cloudflare Organizations ist jetzt für Enterprise-Kunden und MSSP/Distributor-Partner allgemein verfügbar und bietet einen übergeordneten Container zur zentralen Verwaltung von Accounts, Mitgliedern, Analysen und gemeinsamen Richtlinien, während Organization Roles weiterhin in der Beta bleibt.

Cloudflare Organizations is now generally available for Enterprise customers and MSSP/Distributor partners.

Organizations provides a top-level container for centrally managing accounts, members, analytics, and shared policies. Organization Super Administrators receive implicit access to every account in their Organization without requiring separate account memberships.

Enterprise customers can manage accounts in a single-tier Organization. MSSP/Distributor partners can use nested sub-organizations to manage customer accounts.

Organization Roles remains in beta, and current product limitations still apply.

For more information, refer to Cloudflare Organizations and current limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Kein Datum in der Quelle. Angezeigt ist der Tag, an dem wir den Eintrag erstmals gesehen haben.

Erstmals gesehen am .

Storage von Cloudflare

Wrangler 4.126.0 für retryAlarm in lokaler Entwicklung

Für die lokale Entwicklung erfordert die Option retryAlarm von ctx.abort() Wrangler 4.126.0 oder neuer.

For more information, refer to ctx.abort().

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Agent Framework von Microsoft

Microsoft Agent Framework dotnet-1.24.0

Das .NET-Release 1.24.0 enthält unter anderem Korrekturen beim Erhalt von Session-State und Request-Nachrichten, strengere Validierung (deklarative Identifikatoren, LocalCodeAct, Handoff-Requests), isolierte GitHub-Copilot-Attachments sowie ein stabilisiertes Anthropic-Agent-Paket.

Changes:

  • 245d4284a5018b7f446b5eac4d3add1fa5547229 .NET: Restore source-only release solution filter (#9140) [ #8537 ]
  • d0ccaa62761ec36c59c139940797978623fb630a .NET: Preserve explicit null session state across roundtrips (#9012)
  • 279d97f75cb2e7eee885dcdc2c741ef7361ee903 .NET: Honor disabled recent search memory (#9013)
  • 41e785fb9a3c853272ce0fbd2eb93364e9d1de13 .NET: Preserve lazy request messages through agent invocation (#9017)
  • 9251bc9911d30f5035b4a75cd1c61f96c90f38a6 .NET: Update version for 1.24.0 release (#9120)
  • 73a96cb1a90213dfc2b1d36e7c7250559fb28d5d .NET: Stabilize Anthropic agent package (#9111) [ #9110 ]
  • 0774607d8d3fa8a3f50cd5bda7b4c7ad400403f3 .NET: Reject sensitive declarative identifiers (#9071)
  • 41c4f1c9b0242cfc3f2567db9f9c9a462982a4e7 .NET: Harden LocalCodeAct capability validation (#9057)
<details><summary><b>See More</b></summary>
  • b9d24c8fb484c8330abe8bb9e7500ca3c3bbf46c .NET: test: add loopback destination regression coverage (#9064)
  • bd5ab48cfdebb49b9223de0fc75c7141641927f3 .NET: Validate handoff request lifecycle before routing (#8855)
  • 636e8562d1db4e678e0bb88f602e0bbc7318f6a4 .NET: Synchronize background task metadata and defer publication until session creation (#8933)
  • 6ef0b73ed8ee5ae9a5cdc709edc5bfc9443d91cb .NET: Isolate GitHub Copilot attachment staging (#8846)
  • 52fed574f05aa4c22ae4cc024679d501ec5f327a .NET: Preserve atomic cache creation across factory failures (#8931) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Log-Explorer-Datasets werden jetzt über die Logs-Seite abgefragt

Log-Explorer-Datasets werden nun auf der Logs-Seite unter Observability im Cloudflare-Dashboard mit gemeinsamem Filter-Builder, SQL-Editor und Visualisierungen abgefragt, das Menü „Log Explorer“ entfällt in der Navigation, und aktivierte Datasets sowie gespeicherte Abfragen funktionieren weiter.

Log Explorer

Log Explorer datasets are now queried from the Logs page under Observability in the Cloudflare dashboard. The Logs page brings Log Explorer and Workers Observability datasets together with a shared filter builder, SQL editor, and visualizations.

As part of this change, the Log Explorer menu is no longer shown in the dashboard navigation.

  • Your enabled datasets, saved queries, and SQL queries continue to work on the Logs page.
  • To manage datasets, open the dataset selector on the Logs page and select Configure next to the Log Explorer datasets.
  • The previous Log Search page remains available at its direct URL.

For more information, refer to Log Search and the Logs overview.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

OAuthResourceServer und weitere Helfer im Workers OAuth Provider

OAuthResourceServer veröffentlicht RFC-9728-Metadaten und weist Tokens für fremde Ressourcen ab, außerdem gibt es neue Helfer wie Sliding Refresh Token Expiry mit refreshTokenIdleTTL und purgeExpiredData(); bei den meisten 0.x-Deployments ist nur resourceMetadata: { resource } zu ergänzen.

[[services]] binding = "AUTH_SERVER" service = "auth-server" entrypoint = "AuthServer"


`OAuthResourceServer` publishes the [RFC 9728 ↗︎](https://datatracker.ietf.org/doc/html/rfc9728) protected resource metadata that MCP clients use to find your authorization server. It answers requests without a token with a `401` challenge that points to that metadata. It also rejects tokens issued for any other resource.

You can still use `OAuthProvider` as both the authorization server and the MCP server. For most 0.x deployments, the only required change is to add `resourceMetadata: { resource }`.

#### Other updates and helpers

- [Consent page ↗︎](https://github.com/cloudflare/workers-oauth-provider/blob/main/docs/consent-page.md) and [upstream sign-in ↗︎](https://github.com/cloudflare/workers-oauth-provider/blob/main/docs/upstream-sign-in.md) helpers implement the MCP confused deputy protections.
- [Sliding refresh token expiry ↗︎](https://github.com/cloudflare/workers-oauth-provider/blob/main/docs/advanced-configuration.md#sliding-expiry) with `refreshTokenIdleTTL`.
- [Resumable KV cleanup ↗︎](https://github.com/cloudflare/workers-oauth-provider/blob/main/docs/advanced-configuration.md#kv-cleanup) with `purgeExpiredData()`.
- An [internal reason ↗︎](https://github.com/cloudflare/workers-oauth-provider/blob/main/docs/advanced-configuration.md#the-internal-reason) on every error passed to `onError`.

#### Upgrade with the migration skill

npmyarnpnpmbun

``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Log Explorer-Datasets jetzt über Observability Logs abfragbar

Log Explorer-Datasets werden jetzt auf der Logs-Seite unter Observability abgefragt, das Log Explorer-Menü entfällt in der Navigation, und bestehende Datasets sowie gespeicherte Abfragen funktionieren weiter.

Log Explorer datasets are now queried from the Logs page under Observability in the Cloudflare dashboard. The Logs page brings Log Explorer and Workers Observability datasets together with a shared filter builder, SQL editor, and visualizations.

As part of this change, the Log Explorer menu is no longer shown in the dashboard navigation.

  • Your enabled datasets, saved queries, and SQL queries continue to work on the Logs page.
  • To manage datasets, open the dataset selector on the Logs page and select Configure next to the Log Explorer datasets.
  • The previous Log Search page remains available at its direct URL.

For more information, refer to Log Search and the Logs overview.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Cloudflare Organizations ist allgemein verfügbar

Cloudflare Organizations ist für Enterprise-Kunden und MSSP/Distributor-Partner allgemein verfügbar, während Organization Roles weiterhin in der Beta bleibt.

Cloudflare Organizations is now generally available for Enterprise customers and MSSP/Distributor partners.

Organizations provides a top-level container for centrally managing accounts, members, analytics, and shared policies. Organization Super Administrators receive implicit access to every account in their Organization without requiring separate account memberships.

Enterprise customers can manage accounts in a single-tier Organization. MSSP/Distributor partners can use nested sub-organizations to manage customer accounts.

Organization Roles remains in beta, and current product limitations still apply.

For more information, refer to Cloudflare Organizations and current limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Cloudflare Organizations ist allgemein verfügbar

Cloudflare Organizations ist für Enterprise-Kunden und MSSP/Distributor-Partner allgemein verfügbar und bietet einen zentralen Container zur Verwaltung von Accounts, Mitgliedern, Analytics und gemeinsamen Richtlinien, während Organization Roles weiterhin in der Beta bleibt.

Cloudflare Fundamentals Cloudflare One Gateway Organizations

Cloudflare Organizations is now generally available for Enterprise customers and MSSP/Distributor partners.

Organizations provides a top-level container for centrally managing accounts, members, analytics, and shared policies. Organization Super Administrators receive implicit access to every account in their Organization without requiring separate account memberships.

Enterprise customers can manage accounts in a single-tier Organization. MSSP/Distributor partners can use nested sub-organizations to manage customer accounts.

Organization Roles remains in beta, and current product limitations still apply.

For more information, refer to Cloudflare Organizations and current limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

AI Gateway von Cloudflare

AI Gateway: Einheitliche HTTP-401-Antwort bei abgelehnten Provider-Zugangsdaten

Die AI Gateway REST API (POST /ai/run) liefert bei abgelehnten Provider-Zugangsdaten nun einheitlich HTTP 401 mit Fehlercode 2009 statt provider-spezifischer Antworten, und Anwendungen sollten 401 als ungültige Provider-Credentials behandeln.

AI Gateway's REST API now returns consistent responses when an AI provider rejects credentials. The change applies to POST /ai/run ↗︎.

Scenario

Previous AI Gateway response

New AI Gateway response

ElevenLabs

Provider-specific UserCredentialsError with HTTP 403

HTTP 401 with error code 2009

Google Vertex

HTTP 500 for rejected credentials, with upstream retries

HTTP 401 with error code 2009; the request fails without retrying the provider

All other providers

HTTP 402 or another provider-specific status for rejected credentials

HTTP 401 with error code 2009

When using Unified Billing, the provider rejects the credentials

Provider-specific authentication error

HTTP 503

Update applications that handle AI Gateway REST API errors to treat HTTP 401 as an invalid or rejected provider credential.

For details about providing provider credentials, refer to Bring your own provider keys.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Gateway: Einheitliche Fehlerantworten bei abgelehnten Provider-Zugangsdaten

Die AI Gateway REST API (POST /ai/run) liefert bei von Providern abgelehnten Zugangsdaten nun einheitlich HTTP 401 mit Fehlercode 2009 statt provider-spezifischer Antworten (bei Google Vertex ohne Wiederholungsversuche), und bei Unified Billing HTTP 503.

AI Gateway's REST API now returns consistent responses when an AI provider rejects credentials. The change applies to POST /ai/run ↗︎.

Scenario

Previous AI Gateway response

New AI Gateway response

ElevenLabs

Provider-specific UserCredentialsError with HTTP 403

HTTP 401 with error code 2009

Google Vertex

HTTP 500 for rejected credentials, with upstream retries

HTTP 401 with error code 2009; the request fails without retrying the provider

All other providers

HTTP 402 or another provider-specific status for rejected credentials

HTTP 401 with error code 2009

When using Unified Billing, the provider rejects the credentials

Provider-specific authentication error

HTTP 503

Update applications that handle AI Gateway REST API errors to treat HTTP 401 as an invalid or rejected provider credential.

For details about providing provider credentials, refer to Bring your own provider keys.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

wrangler 4.148.0: neue Queues-Flags und assets.base_path

wrangler 4.148.0 ergänzt für wrangler queues subscription create die für die Quelle artifacts.repo nötigen Flags --source-namespace und --source-repo-name und führt assets.base_path ein, mit dem ein Asset-Verzeichnis unter einem öffentlichen URL-Präfix ausgeliefert wird.

Minor Changes

  • #16051 b4e1299 Thanks @devteamaegis! - Add --source-namespace and --source-repo-name to wrangler queues subscription create for the artifacts.repo source

    The Event Subscriptions API requires source.namespace and source.repo_name for artifacts.repo subscriptions, but Wrangler had no way to pass them, so --source artifacts.repo always failed with a validation error. Both flags are now required for this source, and wrangler queues subscription get shows the subscription's resource as <namespace>/<repo-name>.

  • #15998 b75421f Thanks @dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

create-cloudflare 2.73.3: aktualisierte Abhängigkeiten

create-cloudflare 2.73.3 aktualisiert die Abhängigkeiten create-next-app (16.3.8), create-analog (2.8.0) und @angular/create (22.2.1).

Patch Changes

  • #16057 ad54578 Thanks @dependabot! - Update dependencies of "create-cloudflare"

    The following dependency versions have been updated:

    Dependency From To
    create-next-app 16.3.6 16.3.8
  • #16058 f67fb2b Thanks @dependabot! - Update dependencies of "create-cloudflare"

    The following dependency versions have been updated:

    Dependency From To
    create-analog 2.7.5 2.8.0
  • #16060 17c6c0d Thanks @dependabot! - Update dependencies of "create-cloudflare"

    The following dependency versions have been updated:

    Dependency From To
    @angular/create 22.2.0 22.2.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

@cloudflare/workers-utils 0.47.0: Unterstützung für assets.base_path

@cloudflare/workers-utils 0.47.0 unterstützt assets.base_path für Workers Assets, sodass ein Asset-Verzeichnis unter einem öffentlichen URL-Präfix bereitgestellt werden kann, ohne das Layout auf der Festplatte zu ändern.

Minor Changes

  • #15998 b75421f Thanks @dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }
    

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

Patch Changes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

@cloudflare/workers-auth 0.13.0: Option temporaryAccountLogger

@cloudflare/workers-auth 0.13.0 führt die Option temporaryAccountLogger ein, mit der Hinweise zu temporären Konten, etwa an stderr, umgeleitet werden können.

Minor Changes

  • #16068 26e03e2 Thanks @edevil! - Add a temporaryAccountLogger option for temporary-account notices

    AuthContext.temporaryAccountLogger receives the terms notice, the proof-of-work message, and the "Temporary account ready" claim details. A CLI whose commands write parseable output to stdout can route these messages to stderr. When it is not set, the messages go to logger as before.

Patch Changes

Originalquelle(öffnet in neuem Tab)Problem melden