C

Cloudflare Changelog

C
Cloudflare Changelog Cloud

Radar - AS-level connectivity and upstream providers on Cloudflare Radar

Radar expands its Routing section ↗ with two widgets on AS pages, such as AS13335 ↗, that describe how a network reaches the rest of the Internet: the paths it takes toward the Tier-1 ↗ networks, and the mix of direct upstreams carrying its routes. Both are derived from RouteViews ↗ RIB snapshots, unioned across selected collectors. AS-level connectivity The AS-level connectivity graph aggregates…

C
Cloudflare Changelog Cloud

Radar - Radar Researcher beta and WebMCP support now available

Cloudflare Radar now includes Radar Researcher ↗, a beta AI-powered assistant for exploring Internet trends and traffic data in plain language. Open Researcher from the header on any Radar page to ask questions by voice or text, receive explanations, and view interactive charts based on Radar API data. To ask about a specific chart, select Explain with AI to start a conversation with its underlyin…

C
Cloudflare Changelog Cloud

Cloudflare Mesh, Cloudflare One - Container image for Cloudflare Mesh

Cloudflare Mesh nodes can now run as Docker containers. The cloudflare/mesh ↗ image is available on Docker Hub for Docker Compose, Kubernetes, and any OCI-compatible runtime — no host-level package installation required. The image supports amd64 and arm64 architectures and includes built-in source NAT so return traffic routes correctly without VPC route table changes. Deployment patterns Docker Co…

C
Cloudflare Changelog Cloud

AI Gateway, Workers AI - Workers AI and AI Gateway unify model access and billing

Workers AI and AI Gateway now provide a unified path for accessing models and managing inference traffic. Use the same AI binding and REST API to call models hosted on Workers AI or by supported third-party providers, with AI Gateway providing observability, logging, caching, security, and billing controls. Unified entrypoints and observability The AI binding supports both Workers AI and third-par…

C
Cloudflare Changelog Cloud

Browser Run - Introducing Kitesurf, an agent-first browser on Browser Run

Kitesurf is Cloudflare's new stateless, highly scalable browser that runs entirely on top of Workers and is designed for AI agents. It is available for free while in beta. Compared to Chromium, Kitesurf uses 3–7× less CPU and memory for common agentic tasks like screenshots and HTML extraction, so you can run more sessions and scale better for bursty, AI-driven workloads. Your existing clients alr…

C
Cloudflare Changelog Cloud

AI Search - AI Search makes it easier to build a search engine for your data

AI Search gets you from a data source to a working search endpoint quickly. This release adds what you need to put that endpoint in front of real users: your own domain, authentication, and one endpoint across several instances. It also adds crawling for sites without a complete sitemap, so your index covers everything you want it to find. Each of the following is a new option. The previous behavi…

C
Cloudflare Changelog Cloud

AI Gateway - Track AI spend and catch anomalous usage with User Insights

AI Gateway now includes User Insights, a dashboard that gives you two things at once: clear visibility into how much your organization spends on AI, and a security signal that surfaces users whose usage suddenly looks abnormal. It works on the traffic already flowing through your gateway, so there is no additional setup. On the spend side, User Insights shows organization-wide totals for cost, req…

C
Cloudflare Changelog Cloud

Cloudflare Fundamentals - Improved publisher verification details on OAuth consent screens

OAuth consent screens now display a shield icon with explanatory text beneath the consent screen title. Each shield icon indicates who owns the application and whether its domain ownership is verified. Green filled shield: Cloudflare owns and manages the application. Blue outlined shield: A third-party application with verified ownership of its domain. Amber filled shield: A third-party applicatio…

C
Cloudflare Changelog Cloud

AI Gateway, Access - Identity-aware controls are now available in AI Gateway

AI Gateway now integrates with Cloudflare Access, giving you two new capabilities: Protect your gateway endpoint. Put your AI Gateway behind Access so you can set policies that control who is allowed to call a specific gateway's endpoint. Identity-aware controls. When traffic reaches AI Gateway through an Access-protected custom domain, AI Gateway can use the authenticated user's Access identity i…

C
Cloudflare Changelog Cloud

Vectorize - Vectorize indexes now support up to 20 million vectors

You can now store up to 20 million vectors in a single Vectorize index, doubling the previous limit of 10 million vectors. This enables larger-scale semantic search, recommendation systems, and retrieval-augmented generation (RAG) applications without splitting data across multiple indexes. Vectorize continues to support indexes with up to 1,536 dimensions per vector at 32-bit precision. Refer to…

C
Cloudflare Changelog Cloud

Cloudflare Fundamentals - Create Free accounts from the dashboard

You can now create standalone Free accounts directly from the Cloudflare dashboard using the new Create Account button. This feature is currently available to all users. When creating a Free account: You can create up to 5 Free accounts. Your user account must have at least 7 days of tenure to be eligible. The account is created immediately and ready to use. To create a Free account, go to the Clo…

C
Cloudflare Changelog Cloud

Artifacts, Workflows - Build and deploy Artifacts repos on every push

You can now run your CI/CD pipeline on your Artifacts repo by defining a CI Workflow with the CI SDK ↗, automatically triggered on Artifacts push events. This allows you to: Automatically build and deploy application code stored in Artifacts. Run linting, type checking, tests, and other checks on every push. Reuse dependencies when the lockfile (i.e. pnpm-lock.yaml) has not changed. Stop deploymen…

C
Cloudflare Changelog Cloud

Agents, Workers - Agent traces for Think, Flue, and AI SDK instrumented by Agents SDK

Agent tracing is now available for applications built with the Agents SDK. Traces show each agent turn alongside model calls, tool runs, approvals, token usage, and Workers runtime operations. Turn on Workers tracing in your Wrangler configuration: { "$schema": "./node_modules/wrangler/config-schema.json", "observability": { "traces": { "enabled": true } } }[observability.traces] enabled = true Th…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-08-04

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions. Key Findings CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests. CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Ac…

C
Cloudflare Changelog Cloud

Workers - AI agents can debug Workers with local tracing

wrangler dev and vite dev automatically capture structured OpenTelemetry traces and correlated console logs during local Worker invocations. Debug with AI agents When the tooling detects an AI agent session, it prints a terminal hint pointing to the Local Explorer API at /cdn-cgi/explorer/api. The API serves an OpenAPI schema and exposes a read-only observability query endpoint for discovering tel…

C
Cloudflare Changelog Cloud

WAF - WAF Release - Scheduled changes for 2026-08-10

Announcement DateRelease DateRelease BehaviorLegacy Rule IDRule IDDescriptionComments2026-08-042026-08-10LogN/A...94f3006bvBulletin - Remote Code Execution - CVE:CVE-2026-61511This is a new detection.2026-08-042026-08-10LogN/A...098b749eVersion Control - Information Disclosure - BetaThis is a beta detection and will replace the action on original detection "Version Control - Information Disclosure…

C
Cloudflare Changelog Cloud

R2, R2 Data Catalog - Billing is now enabled for R2 Data Catalog

Billing is now enabled for R2 Data Catalog on non-enterprise accounts. R2 Data Catalog usage beyond the included free tier will appear on your next invoice. R2 Data Catalog charges based on two dimensions, in addition to standard R2 storage and operations: Catalog operations: $9.00 / million operations for metadata requests such as creating tables, reading table metadata, and updating table proper…

C
Cloudflare Changelog Cloud

R2 SQL - Billing is now enabled for R2 SQL

Billing is now enabled for R2 SQL on non-enterprise accounts. R2 SQL usage beyond the included free tier will appear on your next invoice. R2 SQL charges based on a single dimension: Data scanned: $0.0025 / GB ($2.50 / TB) of compressed data read from R2 to execute your query. All plans include 10 GB of data scanned per month. Each query is billed for a minimum of 10 MB of data scanned. R2 SQL pri…

C
Cloudflare Changelog Cloud

Pipelines - Billing is now enabled for Pipelines

Billing is now enabled for Cloudflare Pipelines on non-enterprise accounts. Pipelines usage beyond the included free tier will appear on your next invoice. Pipelines charges based on two usage dimensions. Ingress into a Pipeline stream remains free regardless of volume: SQL transforms: $0.04 / GB for stateless transforms (filter, reshape, unnest, cast, compute). Sinks (egress): $0.03 / GB for JSON…

C
Cloudflare Changelog Cloud

Access - Control authorization cookies for multi-domain Access applications

Cloudflare Access administrators can now control whether a self-hosted application preemptively sets authorization cookies across its public hostnames. Previously, Access automatically used eager redirects for applications with five or fewer hostnames. Applications with more than five hostnames received cookies as users visited each hostname. Administrators can now choose either behavior, regardle…

C
Cloudflare Changelog Cloud

Workers - Python and JavaScript Workers can now call each other via RPC

You can now call methods between Python and JavaScript Workers using Workers RPC. This works through Service bindings without extra dependencies, schema definitions, or serialization code. Cross-language RPC calls behave like ordinary function calls. Exceptions propagate to the call site. You can pass structured cloneable types ↗ as parameters or return values, and Pyodide Foreign Function Interfa…

C
Cloudflare Changelog Cloud

Agents, Workers - Preview: @cloudflare/computer agent runtime

We're releasing an early preview of @cloudflare/computer ↗, an open-source agent runtime that gives every agent its own computer. The runtime dynamically orchestrates between fast, efficient isolates and full Linux containers, so the agent always runs on the right compute primitive for the task at hand. @cloudflare/computer provides a virtual filesystem backed by SQLite, which you can populate fro…

C
Cloudflare Changelog Cloud v2026.7.1210.1

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.7.1210.1)

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake. Fixed issue where a certificate error could be i…

C
Cloudflare Changelog Cloud v2026.7.1210.1

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.7.1210.1)

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Improved connection reliability: the client now swaps protocol order after repeated connectivity-check failures, which helps when HTTP/3 is blocked after the QUIC handshake. Fixed issue where a certificate error could be inc…

C
Cloudflare Changelog Cloud

Browser Run - Browser Run adds a Playground to the Cloudflare dashboard

Browser Run now includes a Playground in the Cloudflare dashboard. Use it to try Quick Actions against a live browser without creating a Worker, installing an SDK, or deploying code first. The Playground helps you test a target URL or raw HTML input, tune viewport and page-load settings, preview the output, and copy working code for the same request. With the Playground, you can: Capture visuals a…

C
Cloudflare Changelog Cloud

Access - Static OAuth client credentials for MCP server portals

MCP server portals can now connect to upstream MCP servers that require a pre-registered OAuth client. This supports OAuth providers that do not offer Dynamic Client Registration or have disabled it. This unlocks portal connections to major SaaS providers such as Slack and GitHub, whose MCP servers do not yet support DCR. When adding an MCP server, administrators can enter the client ID and client…

C
Cloudflare Changelog Cloud

Workers, Durable Objects - Inspect Worker startup performance with Wrangler

wrangler check startup now reports your Worker's raw and compressed bundle sizes. It also summarizes local CPU activity during startup directly in your terminal. Large bundles and costly startup work can introduce cold-start latency, so use this command to find code and large dependencies that slow your Worker before it handles requests. The summary includes sampled, active, garbage collection, an…

C
Cloudflare Changelog Cloud

Stream - Rotate Stream broadcast keys for live inputs

You can now rotate the broadcast credentials for a Stream live input without changing the live input identifier. Use key rotation when live input credentials may have been shared with the wrong audience, exposed in client code or a screenshare, or need to be refreshed as part of your security process. Rotating keys revokes the old credentials, disconnects broadcasts using stale credentials, and re…

C
Cloudflare Changelog Cloud

Access - Admins can turn on Code Mode by default for MCP portal users

MCP server portals now support four Code Mode policies: Off, Opt-in, On by default, and Enforced. Admins can choose whether Code Mode is unavailable, optional, enabled by default, or required for every session. Existing portals retain their current behavior. Portals that previously allowed Code Mode use Opt-in, while portals that did not allow Code Mode use Off. New portals also use Opt-in by defa…

C
Cloudflare Changelog Cloud

Workers - Node.js 24 is now the default for Workers Builds

Workers Builds now uses Node.js 24.18.0 by default. The build image preinstalls Node.js 22.23.2 and 24.18.0. You can continue to override the default with the NODE_VERSION environment variable, an .nvmrc file, or a .node-version file. For more information, refer to Override default versions.