Catalog / Infrastructure

Cloudflare Developer Platform changelog

Cloudflare Developer Platform last published on 10 Oct 2026, yesterday.

Workers, Pages, R2, D1 and the rest of the developer platform, tracked from the public changelog.

SubscribeCloudflare Developer Platform as markdown, for pasting into a model
Collected
205 releases back to 7 Aug 2026
Source
developers.cloudflare.com
Project
developers.cloudflare.com
Feed
RSS

Read on 28 of the 30 days on record, last today. Collection status

Version history

2026205 releases
Agents - Cloudflare API MCP server serves Cloudflare skills

The Cloudflare API MCP server now serves Cloudflare skills ↗︎ through the Skills over MCP extension ↗︎. MCP clients that support the extension discover the skills with skills/list and read their files at skill://<name>/<path>. To use them,

added
R2 - R2 bandwidth by Cloudflare location

You can now view R2 bandwidth by the Cloudflare location that served each request in the Cloudflare UI. This helps you see which locations consume the most bandwidth with options to select a specific bucket and download (read) vs upload (wr

WAF, Rules - Failed detections field available in Rules

You can now use cf.appsec.request.failed_detections to control how your rules handle requests when a security detection reports a failure. The field is an Array<String> of detection IDs that reports failures from content scanning, WAF attac

security
WAF - Updated unsafe topic detection for AI Security for Apps

AI Security for Apps now supports an updated set of categories for detecting unsafe topics in incoming prompts. The values available in cf.llm.prompt.unsafe_topic_categories have changed. Existing WAF custom rules remain valid, but rules th

securitychangedremoved
DNS - Warnings when approaching your DNS records quota

The DNS records page in the Cloudflare dashboard now shows a warning once you have used 85% of your DNS records quota. The warning reflects the quota that applies to you. If your zone has its own quota, the warning shows that zone's usage.

WAF - WAF Release - 2026-10-06

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule. Key Findings CVE-202

securityadded
WAF - WAF Release - Scheduled changes for 2026-10-12

Announcement DateRelease DateRelease BehaviorLegacy Rule IDRule IDDescriptionComments2026-10-062026-10-12DisableN/A...02751ef3Generic Rules - Template Injection - 2 - BetaThis rule will be merged into the original rule "Generic Rules - Temp

AI Gateway, Web Search API - Introducing Web Search API

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff. At launch, yo

added
Analytics - 30 days of analytics data on every plan

Every plan now gets at least 30 days of analytics data. Adaptive analytics datasets, such as HTTP requests, security events, and DNS analytics, retain at least 31 days of data for Free and Pro domains, and you can query up to 30 days in a s

security
D1 - United States jurisdiction

You can create D1 databases with the us jurisdiction. These databases run and persist data within the United States. Use this option for regional data residency requirements. To create a database with the us jurisdiction, run: npx wrangler@

AI Search - AI Search is generally available

AI Search is now generally available. Usage-based billing begins on November 1, 2026, with included monthly ingestion, storage, semantic query, and full-text query usage. Cloudflare will send a reminder email the week before billing begins.

added
Artifacts, Workers - Artifacts is now in open beta

Artifacts, Cloudflare's versioned file system that speaks Git, is now in open beta. Artifacts is built for scale, so you can create a repository per project, user, session, or task. With Artifacts, you can: Deploy repositories to Workers —

changed
Rules - Handle missing values with coalesce()

The coalesce() function returns the first argument that is not nil. Use it to provide a fallback in rule expressions: http.request.uri.path eq coalesce(http.request.uri.args["expected_path"][0], "/") For details, refer to the coalesce() fun

Rules - Compare dynamic values in Rules expressions

Cloudflare Rules expressions now support dynamic values on both sides of equality and ordering comparisons. You can compare request fields or function results with one another. For example, compare the current request path with its original

WAF - WAF Release - 2026-10-01 - Emergency

This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors. Key Findings CVE-2026-88771: An improper input validation

securityaddedchanged
Workers - Web Crypto adds ML-KEM and ML-DSA support

The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data. The opt-in API also adds key encapsulation and decapsulation meth

added
Containers - Snapshot and restore Container filesystem

Containers now support snapshot APIs in public beta for saving and restoring point-in-time filesystem state. Create a snapshot first, then pass it back to start() to restore files after container sleep, restart, or handoff to another Durabl

added
AI Gateway - Pay for AI inference with Machine Payments

AI Gateway now supports Machine Payments in beta. With Machine Payments, clients can use the x402 protocol to pay for eligible inference requests directly from a stablecoin wallet instead of maintaining a prepaid credit balance. Machine Pay

logpush, Logs - Transformers are now generally available

Transformers are now generally available for supported Logpush datasets on Free, Pro, Business, and Enterprise plans. Use SQL to filter records, reshape fields, redact sensitive values, compute new fields, or add metadata before Logpush del

added
Monetization Gateway - Monetization Gateway closed beta

Monetization Gateway is now available in closed beta. Sellers can use it to charge agents for access to APIs, Model Context Protocol (MCP) tools, sites, and datasets. Sellers (domain owners) define which requests require payment, the cost,

WAF - WAF Release - 2026-09-30

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts. Key

securityadded
Cache - Invalidate cached content instead of purging it

You can now invalidate cached content instead of purging it. Invalidation marks matching content as stale. On the next request, Cloudflare revalidates the content with your origin. If your origin responds with 304 Not Modified, Cloudflare r

addedchanged
Cache - Purge now forces a cache miss for Cache Reserve content

Purge requests now force a cache miss for Cache Reserve content, regardless of purge type. Previously, purging by cache tag, hostname, prefix, or everything marked matching Cache Reserve content for revalidation. Purging by URL already remo

addedchangedremoved
Workers, Cloudflare CLI - Cloudflare CLI is now in beta

The Cloudflare CLI, cf, is now in beta. cf is one command-line interface for the public Cloudflare API and for Workers projects. Use it to manage zones, DNS, storage, and security settings, and to create, develop, and deploy Workers, withou

securityadded
Browser Run, Queues - Subscribe to Browser Run crawl events

Browser Run crawl jobs can publish lifecycle events to Cloudflare Queues. Subscribe to started, updated, and finished events to track progress or trigger downstream processing without polling. To create an account-level subscription, run th

Email Service - Suppress recipients for one sending domain

Email Sending suppressions now have a scope: account: The suppression applies to every sending domain and subdomain in your account. This is the default. sending_domain: The suppression applies to one sending domain only. A suppression for

added
WAF - WAF Release - 2026-09-25 - Emergency

This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits. Key Fin

securityaddedchanged
1.1.1.1 - RFC 8509 root key trust anchor sentinel support

now supports RFC 8509 ↗︎ root key trust anchor sentinels. They let you check whether the responding resolver trusts a DNSSEC root key ahead of a key rollover. To check for KSK-2024 (key tag 38696), query DNSSEC-signed names in dnstest.dev:

R2 - R2 bandwidth usage metrics

New R2 product-level Metrics page in the Cloudflare dashboard shows bandwidth usage. You can view usage across all buckets or per bucket. Go to R2 Metrics ↗ Bandwidth throughput is split by object upload and download. The GraphQL Analytics

added
Cloudflare Images - View transformation analytics in Images

You can now view account-level analytics for your Images transformation usage. Go to Images & Stream > Transformations > Analytics to view sampled estimates of image transformation request traffic, including: Requests by source, split betwe

Access - Automatically manage inactive Access service tokens

Cloudflare Access administrators can now automatically disable or delete inactive service tokens. Administrators can set an inactivity period from 30 to 365 days and choose what Access does when a token reaches that limit. To be eligible fo

Rules - concat() now supports up to 32 arguments

The concat() function in Cloudflare Rules now accepts up to 32 arguments, increased from 16. This allows you to build richer dynamic values directly in Rules expressions and simplify configurations that combine request data. A common use ca

added
WAF - WAF Release - 2026-09-22

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection

added
Workers - Workers Builds now supports Cursor Origin

Workers Builds now supports repositories hosted in Cursor Origin. Connect a Cursor Origin repository to automatically build and deploy production changes, preview non-production branches, and see build status in pull requests. Pushes to you

logpush, Logs - Filter DDoS attack traffic from Logpush jobs

Logpush jobs can now exclude identified distributed denial-of-service (DDoS) attack traffic. This option reduces attack traffic in delivered logs. It supports the http_requests, firewall_events, and network_analytics_logs datasets. In the d

added
Rules - Validate Rulesets changes before deployment

Cloudflare Rules now validates ruleset changes before deployment, helping you catch invalid expressions, action parameters, permission issues, unavailable features, and quota limits without publishing the configuration. The Cloudflare dashb

securityaddedchanged
Workers AI - Reject busy synchronous inference requests

The rejectIfBusy option lets synchronous Workers AI inference requests fail when capacity is unavailable. Use it when your application should not wait in a capacity queue. Pass the option as the third argument to the Workers AI binding: con

added
Bots - Control JavaScript Detections API results

Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections. Turn JavaScript Detections for API traffic on or off in Security > Settings. You c

security
WAF - WAF Release - 2026-09-15

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history. RulesetRule IDLe

added
Workers - Grant teammates and agents access to specific Workers

You can now grant access to specific Workers and choose from four roles to control the level of access you give teammates, agents, and CI/CD workflows. Choose from four roles to control the level of access: Metadata Read-Only: View settings

changed
DNS - Shadowed record warnings are now available for all zones

Cloudflare now displays warnings for shadowed records in all zones. A record is shadowed when a subdomain delegation gives authority for its name, or a name below it, to another set of nameservers. The record remains present, but your zone

Agents - Inspect Voice Agent turn latency and outcomes

@cloudflare/voice v0.4.0 now lets you inspect where each Voice Agent turn spends time and how it ends. client.addEventListener("turnmetrics", (turn) => { console.log(turn.outcome, turn.turnTotalMs); }); About the Voice package The @cloudfla

addedremoved
WAF - WAF Release - 2026-09-10 - Emergency

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts. Key Findings Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmug

securityaddedchanged
AI Gateway - AI Gateway custom costs support cache tokens

AI Gateway custom costs now support cache-read and cache-write token rates. This lets custom cost metrics reflect negotiated cache pricing across providers. Add per_cache_read_token or per_cache_write_token to the cf-aig-custom-cost header:

added
CASB - New CASB integration for Zoom

Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new f

securityadded
Radar - Radar search now includes Internet events

Cloudflare Radar search now includes Internet events and outages alongside existing results. Search event descriptions or related entities, such as locations, ASes, bots, and top-level domains, to find relevant events and open the most rele

changed
WAF - WAF Release - 2026-09-08

This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures. RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew Ac

security
Workers - Miniflare v5 prepares local development for the cf CLI

Miniflare v5 prepares Cloudflare local development tooling for the upcoming cf CLI. Miniflare powers local Workers development behind wrangler dev, the Cloudflare Vite plugin, and @cloudflare/vitest-plugin. Most projects should use those to

breakingaddeddeprecated
Workers - Python 3.14 for Python Workers

Python workers now use Python 3.14 by default. This change applies to all new Python workers using compatibility date 2026-09-08 or later. Internally, this change updates the Pyodide runtime to 314.0.6.

addedchanged
WAF - Enforce positive security with Application Profiles

Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that d

securityadded
Email Service, Workers - Manage Email Routing rules with Wrangler

You can now manage Email Routing rules that route emails to Workers from your Wrangler configuration. Add literal addresses or a catch-all address to the top-level addresses field: { "$schema": "./node_modules/wrangler/config-schema.json",

addedchangedremoved
R2 - R2 Data Access Logs

R2 Data Access Logs are now generally available. Turn on logging for a bucket to record object read, write, list, multipart upload, and delete operations with response status codes below 400. Data Access Logs cover requests made through the

Cache - Configure Origin Range Requests with the Rulesets API

The Rulesets API now supports Origin Range Requests in Cache Rules. This setting lets Cloudflare fetch large files from your origin in cache-aligned byte ranges. Cloudflare may expand a client range and issue several single-range origin req

D1 - D1 enforces free tier daily query limits

Beginning September 1, 2026, D1 queries on the Workers Free plan will fail when an account exceeds the daily row read or row write limits. Queries via the Workers Binding API and the REST API will return errors until the limit resets at mid

added
WAF - WAF Release - 2026-09-01

This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax. Key Findings SQLi Protection: Improved coverage for SQL injection patterns involving WHERE compariso

addedchanged
Load Balancing - Load Balancing now supports pool sets

Cloudflare Load Balancing now supports pool sets through the API. Pool sets combine geographic matching with location-specific traffic steering. One load balancer can now use different routing behavior for different locations. Each pool set

fixed
AI Search - AI Search now supports GLM-5.3 Flash

AI Search now supports @cf/zai-org/glm-5.3-flash for text generation. The model has a 1,048,576-token context window and runs on Workers AI. To configure the model for an AI Search instance, refer to Supported models.

Log Explorer - Improved dataset configuration in Log Explorer

Log Explorer has a refreshed dataset configuration experience in the Cloudflare dashboard. The new controls make it easier to choose which fields and events Log Explorer ingests. Grouped field selection organizes fields by category and show

addedchangeddeprecated
Workers AI - Z.ai GLM-5.3 now available on Workers AI

@cf/zai-org/glm-5.3 is now available on Workers AI. It is Z.ai's flagship agentic coding model, built for long-running, tool-driven development workflows rather than single-turn chat. GLM-5.3 uses the same base model as GLM-5.2, with every

Access - Access service token secrets use a scannable format

Cloudflare Access service token Client Secrets created on or after August 26, 2026, use the format cfast_[40 alphanumeric characters][8-character checksum]. The prefix and checksum make these credentials easier for secret scanning tools to

AI Search - New Workers AI text generation models in AI Search

AI Search now supports six additional Workers AI models for text generation: Model Context window (tokens) @cf/deepseek-ai/deepseek-v4-flash-0731 1,048,576 @cf/deepseek-ai/deepseek-v4-pro-0813 1,048,576 @cf/openai/gpt-oss-120b 128,000 @cf/o

added
Flagship - Create app-scoped API tokens for Flagship

You can now create app-scoped API tokens for Flagship. These tokens grant access only to the Flagship apps you select, instead of every app in the account. When you create a custom token, open the resource dropdown (it defaults to Entire Ac

Log Explorer - Delete Log Explorer datasets

Cloudflare Log Explorer customers can now permanently delete account and zone datasets from the Cloudflare dashboard or API. Deletion protection is enabled by default to prevent accidental data loss. In the dashboard, go to Manage datasets,

changed
WAF - WAF Release - 2026-08-26 - Emergency

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images. Key Findings CVE-2026-75604 affec

securityaddedchanged
Workers AI - Z.ai GLM-5.3 Flash now available on Workers AI

@cf/zai-org/glm-5.3-flash is now available on Workers AI. It is the first natively multimodal model in the GLM-5 series, built on a Mixture-of-Experts architecture with 320B total parameters and 18B active per token. GLM-5.3 Flash is the fi

Access - Grace periods for service token rotation

Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication. The d

changed
Access - Temporarily turn off Access service tokens

Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later. Turning off a to

AI Search - Store larger custom metadata values in AI Search

AI Search supports larger custom metadata values within a shared 10 KiB metadata envelope for each vector. The envelope includes AI Search system metadata and JSON overhead, so it is not a per-field limit. The first 64 UTF-8 bytes of each i

API Shield - Symmetric key support for JWT validation

API Shield JSON Web Token validation now supports symmetric keys that use the HS256, HS384, and HS512 algorithms. You can configure HMAC verification keys in the Cloudflare dashboard or with the Cloudflare API. Cloudflare never stores symme

WAF - WAF Release - 2026-08-25

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode. Key Findings Four new detections

added
Radar - RPKI ASPA path validation on Cloudflare Radar

Radar adds an ASPA validation tool ↗ to its Routing section ↗. Enter a BGP AS_PATH and the tool checks it against the Autonomous System Provider Authorization (ASPA) ↗ records currently published in the RPKI, returning a verdict of Valid, I

addedchanged
Cloudflare Fundamentals - Improved SCIM 2.0 group synchronization

Dashboard SCIM now supports replacing groups using HTTP PUT, as defined by RFC 7644 section 3.5.1 ↗. This allows identity providers to synchronize a group's full state, including its display name, external ID, and members, in a single reque

addedchanged
Containers - Use FUSE in local Containers development

Miniflare now automatically grants local Containers the Docker privileges required for Filesystem in Userspace (FUSE). This applies to wrangler dev, the Cloudflare Vite plugin, and direct Miniflare use. Miniflare grants these privileges whe

Cloudflare Fundamentals - Optional OAuth scopes

We're announcing the GA of Optional OAuth Scopes. OAuth client developers can now classify configured scopes as required or optional in the Cloudflare dashboard. By default, all configured scopes remain required . What's New Optional Scopes

added
AI Gateway - Get 50% off GPT-5.6 Sol through AI Gateway

GPT-5.6 Sol is available through AI Gateway, and for a limited time you can use it at 50% off. If you are already using AI Gateway, point to the openai/gpt-5.6-sol model and the discounted pricing applies automatically — no promo code neede

Email security - Post-quantum key exchange for MX deployments

Cloudflare Email Security now supports post-quantum hybrid key exchange with X25519MLKEM768 on the SMTP connections we make to receive and deliver mail. Deploying Email Security in front of a provider that supports post-quantum hybrid key a

security
R2 - New `us` jurisdiction for R2

R2 now supports a us jurisdiction, which guarantees that bucket data is stored and processed within the United States. Use this jurisdiction when you need explicit US data residency guarantees. Use the jurisdiction-specific S3 endpoint to c

addedchanged
WAF - WAF Release - 2026-08-17

This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640. Key Findings CVE-2026-65640: A remote code execution vulnerability affecting WordPr

securitychanged
Workers AI - Qwen 3.8 27B now available on Workers AI

@cf/qwen/qwen3.8-27b is now available on Workers AI. Qwen 3.8 27B is a 27-billion-parameter instruction-tuned vision language model from Alibaba's Qwen family. It processes images and text together, with reasoning and function calling for a

Artifacts - Data localization support for Artifacts

Artifacts now supports jurisdictions, allowing you to select the European Union or the United States as the only location where repo data is stored and processed. Select a jurisdiction when you create a namespace. Every repo in that namespa

changed
Realtime - Control Realtime SFU DataChannel delivery

Cloudflare Realtime SFU is a WebRTC selective forwarding unit that runs on Cloudflare's global network. It forwards audio, video, and application data between WebRTC clients without requiring you to manage SFU infrastructure or regions. Dat

addedchanged
Support - New Cloudflare Status page

The Cloudflare Status page at www.cloudflarestatus.com ↗ has been rebuilt. It is available at the same address, and every previously documented Status API ↗ endpoint remains supported, so existing bookmarks, integrations, and monitoring con

added
WAF - WAF Release - 2026-08-11

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections. Key Findings A new detection provides protection against vBulletin CVE-2026-61511. Two existing detections h

securityaddedchanged
Turnstile - Turnstile Spin is now generally available

Turnstile Spin is now generally available with three setup paths for creating a Turnstile widget and wiring canonical server-side siteverify into your existing backend. Start in the dashboard, with Wrangler, or from your AI coding agent. Al