C

Cloudflare Changelog

C
Cloudflare Changelog Cloud

Workflows, Workers - Stream Workflow instance events in your Worker or via the API with .subscribe()

You can now stream Workflow instance events via WorkflowInstance.subscribe() and the GET /subscribe API endpoint. Workers and HTTP clients can react to workflow and step events, including attempts, sleeps, waits, and rollbacks, without polling for instance status. A subscription first streams the entire event history of the Workflow instance. After streaming past events, the subscription waits for…

C
Cloudflare Changelog Cloud

Cloudflare One, Access - Access for Infrastructure now supports tagged targets and tag-based target criteria

Access for Infrastructure now integrates with Resource Tagging. You can attach key-value tags to infrastructure targets and use them in access policies. You can manage tags on targets inline when you create or edit a target or through the central Resource Tagging API. Cloudflare keeps tags in sync across both methods. Infrastructure applications also support a target criteria model with include, r…

C
Cloudflare Changelog Cloud

Workers - Grant teammates and agents access to specific Workers

You can now grant access to specific Workers and choose from four roles to control the level of access you give teammates, agents, and CI/CD workflows. Choose from four roles to control the level of access: Metadata Read-Only: View settings, metrics, logs, and traces without access to Worker code or the ability to make changes. Content Read-Only: Read Worker code, settings, and observability data…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-09-15

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history. RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionCommentsCloudflare Managed Ruleset...ca453d31N/ASSRF - Cloud - 3LogBlockThis is a new detection.Cloudflare Manag…

C
Cloudflare Changelog Cloud

WAF - WAF Release - Scheduled changes for 2026-09-22

Announcement DateRelease DateRelease BehaviorLegacy Rule IDRule IDDescriptionComments2026-09-152026-09-22LogN/A...0f0313d6SSRF - Block jar HTTP loopback payloadThis is a new detection.2026-09-152026-09-22LogN/A...5f21b651SSRF - Cloud,Link-Local non-standard IP notationThis is a new detection.2026-09-152026-09-22LogN/A...75cd912aSSRF - Local non-standard IP notationThis is a new detection.2026-09-1…

C
Cloudflare Changelog Cloud

AI Gateway - Prevent Unified Billing fallback for BYOK third-party providers

AI Gateway can now require credentials for third-party provider requests. Credentials must accompany the request or be stored on the gateway. This setting prevents fallback to Unified Billing with Cloudflare-managed credentials. Turn on Require provider credentials in your gateway settings. To use the API, set byok_only to true in the request body of a PUT request to update the gateway: { "byok_on…

C
Cloudflare Changelog Cloud

DNS - Shadowed record warnings are now available for all zones

Cloudflare now displays warnings for shadowed records in all zones. A record is shadowed when a subdomain delegation gives authority for its name, or a name below it, to another set of nameservers. The record remains present, but your zone is not authoritative for it thus Cloudflare will not respond with it to matching DNS queries. These warnings help you find records that may no longer resolve fr…

C
Cloudflare Changelog Cloud

Access - Require fresh authentication for SAML identity providers

Cloudflare Access can now request fresh authentication from a SAML identity provider for every login. Turn on Require reauthentication in the Cloudflare dashboard, or set force_authn to true through the API. Access will then set ForceAuthn to true in signed and unsigned SAML authentication requests. This option is useful when an application requires users to reauthenticate at the identity provider…

C
Cloudflare Changelog Cloud

Browser Run - Control which hostnames Browser Run sessions can access

Browser Run now supports guardrails, which limit a browser session's HTTP and HTTPS requests to permitted hostnames. Use guardrails when you need to: Keep a browser workflow limited to a specific website and its subdomains. Load only known third-party APIs, scripts, images, and fonts. Generate a screenshot or PDF from HTML you provide while preventing it from loading external content. Set guardrai…

C
Cloudflare Changelog Cloud

Data Loss Prevention - Discover where sensitive data goes before you create a Data Loss Prevention policy

Passive Detection for Cloudflare Data Loss Prevention (DLP) lets you learn from your Gateway traffic before deciding what to log or block. Discover the sensitive data types in sampled traffic, explore their destinations, and use the findings to build policies around your organization's needs. The dashboard brings together detections from sampled HTTP request and response bodies. Select an entry to…

C
Cloudflare Changelog Cloud

Agents - Inspect Voice Agent turn latency and outcomes

@cloudflare/voice v0.4.0 now lets you inspect where each Voice Agent turn spends time and how it ends. client.addEventListener("turnmetrics", (turn) => { console.log(turn.outcome, turn.turnTotalMs); }); About the Voice package The @cloudflare/voice package lets you build real-time voice agents with Cloudflare Agents. It streams microphone audio to an Agent over WebSocket, transcribes speech, runs…

C
Cloudflare Changelog Cloud

Workflows - Default instance retention for new Workflows on Workers Paid is seven days

Workflows created on or after September 10, 2026, on the Workers Paid plan retain completed and errored instance state for seven days by default (previously 30 days). The seven day default helps to reduce storage costs by default. The maximum retention limit remains 30 days. The retention period for existing Workflows is unchanged. The Workers Free plan retains its three-day default and limit. To…

C
Cloudflare Changelog Cloud

Containers - Use Cloudflare Containers with Codex via the OpenAI Agents API

The OpenAI Agents API gives your application access to Codex through an OpenAI-managed API. OpenAI manages sessions, orchestration, context compaction, and recovery while your application provides tools and uses Cloudflare Containers as the execution environment. Cloudflare Containers can now provide self-hosted execution environments for the OpenAI Agents API. The open-source OpenAI Agents API Wo…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-09-10 - Emergency

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts. Key Findings Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unaut…

C
Cloudflare Changelog Cloud v2026.8.1290.1

Cloudflare One Client - Cloudflare One Client for macOS (version 2026.8.1290.1)

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM. Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum…

C
Cloudflare Changelog Cloud v2026.8.1290.1

Cloudflare One Client - Cloudflare One Client for Windows (version 2026.8.1290.1)

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page. This beta release includes the following changes and improvements: Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM. Improved DNS reliability on networks with lower MTUs by clamping the TCP maxim…

C
Cloudflare Changelog Cloud

CASB - New CASB integration for Zoom

Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new findings as your environment changes. Zoom is widely used for meetings, webinars, and collaboration. Misconfigurations in account settings, meeting security cont…

C
Cloudflare Changelog Cloud

Browser Isolation, Cloudflare One - Improved iOS tap-to-type experience for Browser Isolation

Browser Isolation has improved the tap-to-type experience for users on iOS devices. Previously, Browser Isolation displayed a full-screen overlay with the message tap to type when users focused a text field. The prompt now appears inline over the focused text field, reducing disruption when users enter text in isolated sessions. If the focused text field is too small to display the full prompt, Br…

C
Cloudflare Changelog Cloud

AI Gateway - AI Gateway custom costs support cache tokens

AI Gateway custom costs now support cache-read and cache-write token rates. This lets custom cost metrics reflect negotiated cache pricing across providers. Add per_cache_read_token or per_cache_write_token to the cf-aig-custom-cost header: { "per_token_in": 0.000001, "per_token_out": 0.000002, "per_cache_read_token": 0.0000001, "per_cache_write_token": 0.0000005 } Cache-token pricing activates wh…

C
Cloudflare Changelog Cloud

WAF - WAF Release - 2026-09-08

This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures. RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionCommentsCloudflare Managed Ruleset...c76ba662N/ANext.js - Image Optimizer Remote Code Execution via Crafted AVIF - BetaLogBlockThis rule is merged into the…

C
Cloudflare Changelog Cloud

Radar - Radar search now includes Internet events

Cloudflare Radar search now includes Internet events and outages alongside existing results. Search event descriptions or related entities, such as locations, ASes, bots, and top-level domains, to find relevant events and open the most relevant Radar view. Event links preserve the event date range, making it easier to investigate what changed before, during, and after an event. These results are a…

C
Cloudflare Changelog Cloud

Workers - Miniflare v5 prepares local development for the cf CLI

Miniflare v5 prepares Cloudflare local development tooling for the upcoming cf CLI. Miniflare powers local Workers development behind wrangler dev, the Cloudflare Vite plugin, and @cloudflare/vitest-plugin. Most projects should use those tools instead of depending on Miniflare directly, and Miniflare v5 will not require any action. The most significant change is a new configuration shape which ali…

C
Cloudflare Changelog Cloud

Cloudflare Fundamentals, Workers - Enterprise customers can self-serve CDN upload limits up to 5 GB

Enterprise customers can now configure a zone's CDN Maximum Upload Size up to 5 GB directly from the Network page in the Cloudflare dashboard. This removes the need to contact your account team or Cloudflare Support when applications need to accept request bodies larger than 500 MB and no greater than 5 GB. The default maximum upload size remains 500 MB. Upload limits above 5 GB still require addi…

C
Cloudflare Changelog Cloud

R2 - R2 Data Access Logs

R2 Data Access Logs are now generally available. Turn on logging for a bucket to record object read, write, list, multipart upload, and delete operations with response status codes below 400. Data Access Logs cover requests made through the S3-compatible API, Cloudflare API and dashboard, Workers bindings, and public buckets through r2.dev or custom domains. Events are available in Workers Observa…

C
Cloudflare Changelog Cloud

Workers - Deploy larger Workers — up to 64 MiB for both free and paid plans

You can now deploy Workers with larger dependencies, heavier frameworks, and more code without hitting size limits. When you deploy a Worker, Wrangler bundles your code and compresses it before uploading. Previously, Cloudflare checked that compressed size and rejected deploys over 3 MB (Free) or 10 MB (Paid). That limit has been removed. Cloudflare now only checks the uncompressed size of your bu…

C
Cloudflare Changelog Cloud

Cache - Configure Origin Range Requests with the Rulesets API

The Rulesets API now supports Origin Range Requests in Cache Rules. This setting lets Cloudflare fetch large files from your origin in cache-aligned byte ranges. Cloudflare may expand a client range and issue several single-range origin requests. Set origin_range_requests.mode to on, off, or default for any traffic matched by a Cache Rule. To override Cloudflare's default Origin Range Requests beh…

C
Cloudflare Changelog Cloud

Workers - Python Workers now support WSGI web frameworks like Django and Flask

Python web frameworks following the Web Server Gateway Interface (WSGI) ↗ or Asynchronous Server Gateway Interface (ASGI) ↗ specification can now be used in Python Workers. Using web frameworks with Python Workers Based on the web framework you are using, you can use either wsgi or asgi from the workers module. WSGI frameworks For WSGI frameworks like Django or Flask: from workers import wsgi from…