releases.sh
Cloudflare

Cloudflare

cloudflare.comInfrastructure
$npx @buildinternet/releases get cloudflare
Recently Shipped294 releases · updated Aug 28, 2026

Recently shipped Access policies bound directly to Workers, DeepSeek V4 with 1M-token context windows, and automatic CASB remediation.

Workers gained default Node.js compatibility and AI-agent debugging.

  • nodejs_compat and nodejs_compat_v2 are enabled by default for compatibility dates of 2026-08-04 or later, so Node.js built-ins like node:crypto, node:fs, and node:http work without extra config.
  • wrangler dev and vite dev now capture OpenTelemetry traces and correlated logs locally, exposing them through a Local Explorer API that AI agents can query to debug and verify fixes.
  • Wrangler and the Vite plugin now detect Node.js compatibility from the compatibility date, matching workerd's behavior.

Workers AI added two flagship models and unified billing with AI Gateway.

  • DeepSeek V4 Flash and Pro are the first Workers AI models with a full 1,048,576-token context window, with thinking mode and function calling.
  • Z.ai GLM-5.3 Flash is the first natively multimodal GLM model on the platform, with 320B total parameters and 18B active per token.
  • The AI binding and REST API now work across Workers AI and third-party providers, with AI Gateway providing observability, caching, and billing controls.

Access and CASB tightened identity and SaaS security.

  • Access policies can now attach directly to a Worker, covering all its domains and preview URLs, or make all Workers private by default.
  • CASB remediation policies automatically fix Microsoft 365 and Google Workspace file-sharing findings or fire webhooks on detection.
  • Service tokens gained scannable cfast_ secrets, rotation grace periods, and the ability to be temporarily disabled.

WAF blocked new RCE and smuggling vectors.

  • Emergency rules cover CVE-2026-75604 (Next.js RCE) and a Next.js Image Optimizer AVIF flaw; four HTTP/2 request smuggling and XSS detections moved from Log to Block.
  • New detections also cover vBulletin CVE-2026-61511, SharePoint CVE-2026-50522, and Rails Active Storage CVE-2026-66066.

Platform and networking updates rounded out the month.

  • Hyperdrive MySQL support, Certificate Transparency Monitoring, Turnstile Spin, and hostname routing for Cloudflare Tunnel and Mesh all reached GA.
  • Kitesurf, a stateless agent-first browser on Browser Run, entered free beta; Email Security added post-quantum key exchange for MX.
  • Log Explorer datasets can now be deleted, and the Azure Functions-based Sentinel connector is deprecated in favor of the CCF connector by 2026-09-14.
AI-generated summaries may contain mistakes.

Sources

Latest releases

See all releases