Traceary

Catalog / Infrastructure

Cloudflare Developer Platform changelog

Workers, Pages, R2, D1 and the rest of the developer platform, tracked from the public changelog.

Latest
26 Aug 2026
Shipped
26 Aug 2026today
Collected
58 releasesback to 7 Aug 2026
Source
developers.cloudflare.com
Project
developers.cloudflare.com
Feed
RSS

Read today, the first day on record. Collection status

Version history

202658 releases
AI Search - New Workers AI text generation models in AI Search

AI Search now supports six additional Workers AI models for text generation: Model Context window (tokens) @cf/deepseek-ai/deepseek-v4-flash-0731 1,048,576 @cf/deepseek-ai/deepseek-v4-pro-0813 1,048,576 @cf/openai/gpt-oss-120b 128,000 @cf/o

added
Flagship - Create app-scoped API tokens for Flagship

You can now create app-scoped API tokens for Flagship. These tokens grant access only to the Flagship apps you select, instead of every app in the account. When you create a custom token, open the resource dropdown (it defaults to Entire Ac

WAF - WAF Release - 2026-08-26 - Emergency

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images. Key Findings CVE-2026-75604 affec

securityaddedchanged
Access - Grace periods for service token rotation

Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication. The d

changed
Access - Temporarily turn off Access service tokens

Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later. Turning off a to

AI Search - Store larger custom metadata values in AI Search

AI Search supports larger custom metadata values within a shared 10 KiB metadata envelope for each vector. The envelope includes AI Search system metadata and JSON overhead, so it is not a per-field limit. The first 64 UTF-8 bytes of each i

WAF - WAF Release - 2026-08-25

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode. Key Findings Four new detections

added
Radar - RPKI ASPA path validation on Cloudflare Radar

Radar adds an ASPA validation tool ↗ to its Routing section ↗. Enter a BGP AS_PATH and the tool checks it against the Autonomous System Provider Authorization (ASPA) ↗ records currently published in the RPKI, returning a verdict of Valid, I

addedchanged
Cloudflare Fundamentals - Improved SCIM 2.0 group synchronization

Dashboard SCIM now supports replacing groups using HTTP PUT, as defined by RFC 7644 section 3.5.1 ↗. This allows identity providers to synchronize a group's full state, including its display name, external ID, and members, in a single reque

addedchanged
Containers - Use FUSE in local Containers development

Miniflare now automatically grants local Containers the Docker privileges required for Filesystem in Userspace (FUSE). This applies to wrangler dev, the Cloudflare Vite plugin, and direct Miniflare use. Miniflare grants these privileges whe

Cloudflare Fundamentals - Optional OAuth scopes

We're announcing the GA of Optional OAuth Scopes. OAuth client developers can now classify configured scopes as required or optional in the Cloudflare dashboard. By default, all configured scopes remain required . What's New Optional Scopes

added
AI Gateway - Get 50% off GPT-5.6 Sol through AI Gateway

GPT-5.6 Sol is available through AI Gateway, and for a limited time you can use it at 50% off. If you are already using AI Gateway, point to the openai/gpt-5.6-sol model and the discounted pricing applies automatically — no promo code neede

Email security - Post-quantum key exchange for MX deployments

Cloudflare Email Security now supports post-quantum hybrid key exchange with X25519MLKEM768 on the SMTP connections we make to receive and deliver mail. Deploying Email Security in front of a provider that supports post-quantum hybrid key a

security
R2 - New `us` jurisdiction for R2

R2 now supports a us jurisdiction, which guarantees that bucket data is stored and processed within the United States. Use this jurisdiction when you need explicit US data residency guarantees. Use the jurisdiction-specific S3 endpoint to c

addedchanged
WAF - WAF Release - 2026-08-17

This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640. Key Findings CVE-2026-65640: A remote code execution vulnerability affecting WordPr

securitychanged
Workers AI - Qwen 3.8 27B now available on Workers AI

@cf/qwen/qwen3.8-27b is now available on Workers AI. Qwen 3.8 27B is a 27-billion-parameter instruction-tuned vision language model from Alibaba's Qwen family. It processes images and text together, with reasoning and function calling for a

Artifacts - Data localization support for Artifacts

Artifacts now supports jurisdictions, allowing you to select the European Union or the United States as the only location where repo data is stored and processed. Select a jurisdiction when you create a namespace. Every repo in that namespa

changed
Realtime - Control Realtime SFU DataChannel delivery

Cloudflare Realtime SFU is a WebRTC selective forwarding unit that runs on Cloudflare's global network. It forwards audio, video, and application data between WebRTC clients without requiring you to manage SFU infrastructure or regions. Dat

addedchanged
Support - New Cloudflare Status page

The Cloudflare Status page at www.cloudflarestatus.com ↗ has been rebuilt. It is available at the same address, and every previously documented Status API ↗ endpoint remains supported, so existing bookmarks, integrations, and monitoring con

added
WAF - WAF Release - 2026-08-11

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections. Key Findings A new detection provides protection against vBulletin CVE-2026-61511. Two existing detections h

securityaddedchanged
Turnstile - Turnstile Spin is now generally available

Turnstile Spin is now generally available with three setup paths for creating a Turnstile widget and wiring canonical server-side siteverify into your existing backend. Start in the dashboard, with Wrangler, or from your AI coding agent. Al