AI Search now supports six additional Workers AI models for text generation: Model Context window (tokens) @cf/deepseek-ai/deepseek-v4-flash-0731 1,048,576 @cf/deepseek-ai/deepseek-v4-pro-0813 1,048,576 @cf/openai/gpt-oss-120b 128,000 @cf/o
Catalog / Infrastructure
Cloudflare Developer Platform changelog
Workers, Pages, R2, D1 and the rest of the developer platform, tracked from the public changelog.
- Latest
- 26 Aug 2026
- Shipped
- 26 Aug 2026today
- Collected
- 58 releasesback to 7 Aug 2026
- Project
- developers.cloudflare.com
- Feed
- RSS
Read today, the first day on record. Collection status
Version history
202658 releases
You can now create app-scoped API tokens for Flagship. These tokens grant access only to the Flagship apps you select, instead of every app in the account. When you create a custom token, open the resource dropdown (it defaults to Entire Ac
Cloudflare Enterprise customers using the Azure Functions-based Microsoft Sentinel connector ↗ must migrate to the Cloudflare for Microsoft Sentinel Codeless Connector Framework (CCF) connector ↗ by 2026-09-14. Microsoft is deprecating the
Cloudflare Radar expands the Radar Researcher ↗ beta with richer sources and new ways to investigate Internet data. Connected insights Radar Researcher responses can now link to relevant Radar pages, reports, and Cloudflare Blog posts. URL
This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images. Key Findings CVE-2026-75604 affec
Cloudflare Access administrators can now choose a grace period when rotating a service token secret. Both secrets remain valid during the grace period, giving administrators time to update services without interrupting authentication. The d
Cloudflare Access administrators can now temporarily turn off service tokens without deleting them. A disabled token cannot authenticate, but its configuration remains available so administrators can turn it on again later. Turning off a to
AI Search supports larger custom metadata values within a shared 10 KiB metadata envelope for each vector. The envelope includes AI Search system metadata and JSON overhead, so it is not a per-field limit. The first 64 UTF-8 bytes of each i
MCP server portals support the stateless MCP 2026-07-28 specification for client and upstream server connections. The portal's /mcp endpoint automatically accepts stateless MCP 2026-07-28 requests and earlier 2025 Streamable HTTP clients. W
By default, an alarm interrupted by ctx.abort() retries after the Durable Object resets. Pass { retryAlarm: false } when the alarm should stop instead: src/index.jsjsimport { DurableObject } from "cloudflare:workers"; export class CleanupTa
This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode. Key Findings Four new detections
Announcement DateRelease DateRelease BehaviorLegacy Rule IDRule IDDescriptionComments2026-08-252026-09-01LogN/A...bcfa0966SQLi - WHERE Comparison With WITH ClauseThis is a new detection.
When you register a Cloudflare One Virtual Appliance, you can now select your hypervisor and download the appliance directly from the dashboard — no need to look up asset URLs. On the Connectors page, select Add an appliance, choose Virtual
Radar adds an ASPA validation tool ↗ to its Routing section ↗. Enter a BGP AS_PATH and the tool checks it against the Autonomous System Provider Authorization (ASPA) ↗ records currently published in the RPKI, returning a verdict of Valid, I
Wrangler and the Cloudflare API MCP server now use optional OAuth scopes. During authorization, you can choose which optional scopes to grant instead of approving every scope requested by each client. The consent dialog now includes the opt
Cloudflare CASB is an API-based (agentless) tool that continuously scans your SaaS and cloud applications for security misconfigurations and data exposure. You can now use CASB remediation policies to automatically fix a finding or send a w
Test scan lets you check how Data Loss Prevention (DLP) evaluates sample content before you apply a profile to production traffic. Paste text, upload a file, or upload a HAR file, then select the profiles you want to test. Test scan sends c
Cloudflare API 403 Forbidden responses now include a documentation_url field that links directly to the API documentation for the endpoint that was denied. This gives developers, administrators, and agents an immediate path to the relevant
Cloudflare Dashboard users can now save login profiles on a device for faster sign-in on future visits. What's New Save login profiles on a device: After a successful sign-in, users can choose to save a login profile on that device. Saved p
Dashboard SCIM now supports replacing groups using HTTP PUT, as defined by RFC 7644 section 3.5.1 ↗. This allows identity providers to synchronize a group's full state, including its display name, external ID, and members, in a single reque
Cloudflare Web Analytics (Real User Monitoring) is rolling out accuracy improvements to client-side soft navigations. This change may alter the volume of pageviews reported in the dashboard and GraphQL API, though the extent depends on your
Browser Run lets you automate headless browsers on Cloudflare's global network. Run full browser sessions for interactive workflows, or use Quick Actions for one-request tasks such as screenshots, PDFs, and capturing page content. If you ar
Miniflare now automatically grants local Containers the Docker privileges required for Filesystem in Userspace (FUSE). This applies to wrangler dev, the Cloudflare Vite plugin, and direct Miniflare use. Miniflare grants these privileges whe
Durable Object namespaces now have a Deployments tab in the Cloudflare dashboard, showing the versions of the backing Worker that are currently live and the traffic split between them. Go to Durable Objects ↗ A Durable Object namespace is b
We're announcing the GA of Optional OAuth Scopes. OAuth client developers can now classify configured scopes as required or optional in the Cloudflare dashboard. By default, all configured scopes remain required . What's New Optional Scopes
Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom dete
A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This release introduces multiple features from our previous beta release into stable release, including: When reauthentication is
Members with only resource-scoped Access roles can now open Access resource list pages in the Cloudflare dashboard and call list endpoints in the API. They no longer need an additional account-scoped read-only role to list resources. The da
GPT-5.6 Sol is available through AI Gateway, and for a limited time you can use it at 50% off. If you are already using AI Gateway, point to the openai/gpt-5.6-sol model and the discounted pricing applies automatically — no promo code neede
Version 1 of the Workers Vitest integration is published as @cloudflare/vitest-plugin ↗. The package was formerly named @cloudflare/vitest-pool-workers. The Vitest configuration API is unchanged. Existing projects must update the dependency
You can now configure origin application settings directly in the Cloudflare dashboard when adding or editing a published application route for a Cloudflare Tunnel. These settings control how cloudflared connects to your origin server and w
Cloudflare Email Security now supports post-quantum hybrid key exchange with X25519MLKEM768 on the SMTP connections we make to receive and deliver mail. Deploying Email Security in front of a provider that supports post-quantum hybrid key a
Load balancing analytics now filters traffic data by pool name instead of pool ID, aligning the query behavior with the pool names displayed in the filter dropdown. Previously, the analytics pool filter queried by internal pool ID while dis
R2 now supports a us jurisdiction, which guarantees that bucket data is stored and processed within the United States. Use this jurisdiction when you need explicit US data residency guarantees. Use the jurisdiction-specific S3 endpoint to c
This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640. Key Findings CVE-2026-65640: A remote code execution vulnerability affecting WordPr
@cf/qwen/qwen3.8-27b is now available on Workers AI. Qwen 3.8 27B is a 27-billion-parameter instruction-tuned vision language model from Alibaba's Qwen family. It processes images and text together, with reasoning and function calling for a
Cloudflare has fixed an issue affecting WebSocket data transfer reporting. HTTP Traffic Analytics and HTTP request logs now correctly count data transferred throughout a WebSocket connection, restoring the correct behavior. During the affec
@cf/deepseek-ai/deepseek-v4-pro-0813 and @cf/deepseek-ai/deepseek-v4-flash-0731 are now available on Workers AI. DeepSeek V4 Flash and DeepSeek V4 Pro are the first Workers AI models with a full one million (1,048,576) token context window.
You now have two new ways to protect your Workers with Cloudflare Access. Protect an application across all its domains at once Until now, if a Worker was reachable on a route, a Custom Domain, and a workers.dev URL, you had to manually add
Artifacts now supports jurisdictions, allowing you to select the European Union or the United States as the only location where repo data is stored and processed. Select a jurisdiction when you create a namespace. Every repo in that namespa
Cloudflare Gateway can now detect software package downloads and give you policy control over supply chain traffic. When a developer or CI/CD pipeline downloads a package through Gateway, the proxy identifies the registry protocol from the
Cloudflare Realtime SFU is a WebRTC selective forwarding unit that runs on Cloudflare's global network. It forwards audio, video, and application data between WebRTC clients without requiring you to manage SFU infrastructure or regions. Dat
Cloud Connector now supports public Oracle Cloud Infrastructure (OCI) Object Storage buckets. You can route matching requests to OCI without managing a separate origin-routing configuration. OCI support uses the Amazon S3 Compatibility API.
Certificate Transparency Monitoring is now generally available ↗ across all Cloudflare plans. Alerts for certificates Cloudflare issues on your behalf (Universal SSL renewals, backup certificates, Advanced Certificate Manager, Total TLS) ar
Cloudflare Email security now lets administrators write their own content-based blocking rules. A new Blocked content area under Policies & rules lets you define a plaintext string or a regular expression, choose whether to scan the message
Infrastructure applications support independent multi-factor authentication (MFA) with FIDO2 keys. You can allow ssh_fido2_key, piv_key, or both in application-level and policy-level MFA settings. Users enroll FIDO2 keys through the App Lau
Cloudflare Gateway now automatically detects Model Context Protocol (MCP) ↗ traffic flowing through your network. MCP is the standard protocol used by AI agents to connect to external tools and data sources. Gateway identifies MCP requests
Gateway HTTP and Network policies now include a Traffic Source selector that identifies how traffic reaches Cloudflare. This allows administrators to write policies that target specific on-ramp methods - for example, applying different rule
Pages now automatically skips a queued build when a newer build for the same project, branch, and deployment target is also queued.
The Cloudflare Status page at www.cloudflarestatus.com ↗ has been rebuilt. It is available at the same address, and every previously documented Status API ↗ endpoint remains supported, so existing bookmarks, integrations, and monitoring con
Hostname routing ↗ is now generally available. Instead of managing static IP lists and routes, you can route traffic by hostname across multiple Cloudflare One connectors: Cloudflare Tunnel: route a private hostname (for example, wiki.inter
This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections. Key Findings A new detection provides protection against vBulletin CVE-2026-61511. Two existing detections h
A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page. This hotfix addresses an uncommon and intermittent case on Windows devices where the device is unable to reconnect after the devi
Real-time Tunnel log streaming is now available in the Cloudflare dashboard under Networking > Tunnels. This brings the same live debugging capability previously only available in the Cloudflare One dashboard, including multi-connector aggr
Turnstile Spin is now generally available with three setup paths for creating a Turnstile widget and wiring canonical server-side siteverify into your existing backend. Start in the dashboard, with Wrangler, or from your AI coding agent. Al
Workers AI and AI Gateway now provide a unified path for accessing models and managing inference traffic. Use the same AI binding and REST API to call models hosted on Workers AI or by supported third-party providers, with AI Gateway provid
Support for MySQL in Hyperdrive is now generally available. You can connect to any MySQL database from your Workers using Hyperdrive. Hyperdrive makes your regional, MySQL databases fast when connecting from Cloudflare Workers. It eliminate
You can now restart a Hyperdrive configuration from the Cloudflare dashboard. Restarting drains the connection pool and forces Hyperdrive to establish new connections to your origin database. Restarting is a break-glass action. Hyperdrive a