Releases Index

BetaWeekly digests are a beta — we're trying something new. Feedback welcome.

Cloudflare opens the agent stack while Next.js patches cache poisoning

September 28 – October 4, 2026

CloudflareVercel
Cloudflare, Vercel

Cloudflare shipped a broad expansion of its agent and data platform this week — a Web Search API, the first in-house Workers AI models, Git-backed Artifacts, and a Sandbox SDK that hands sandboxes to your own Durable Objects — while Next.js issued security patches for a high-severity SSRF bug and cache poisoning in SSG and ISR pages.

Cloudflare builds out the agent stack

The week's biggest theme was giving AI agents real infrastructure to stand on. Cloudflare launched a Web Search API in beta, letting agents query the live web through a choice of Ceramic.ai, Exa, or Linkup, with requests flowing through AI Gateway so they show up in your logs and bill at provider list price with no markup. Grounding models in real results is the point; you can also bring your own provider key.

Two more pieces landed squarely in agent territory. Durable Objects now stay alive while I/O is pending — bindings, RPC calls to other Durable Objects, container monitoring, waitUntil promises, and timers — so a submitted job no longer dies when its client disconnects. And the Artifacts versioned file system entered open beta, a Git-speaking store built so you can keep a repository per project, user, session, or task, deploy them to Workers through Workers Builds, and pick US or EU storage.

The Sandbox SDK hit 1.0, letting your own Durable Object class drive each sandbox container through the container API — choosing image and instance size at start, snapshotting and restoring workspaces, streaming command I/O, and serving authenticated previews from sandbox ports. The Agents SDK added a PiHarness beta for durable long-running Pi agents. Cloudflare also open-sourced its first Workers AI models, Clef and Clef-flash, which return probabilities over typed questions rather than free-form text, plus an RL fine-tuning service for adapting them.

Data residency and an analytics platform go GA

Basin reached general availability as Cloudflare's end-to-end analytics platform — Pipelines for ingestion, Catalog for Iceberg tables, SQL for querying — and each Pipelines stream now ingests up to 1 GB/s, a 200x jump over the old 5 MB/s ceiling. AI Search went GA too with usage-based billing from November 1 and hybrid search on by default.

Data localization got concrete: KV namespace jurisdictions are generally available with eu, us, and fedramp options fixed at creation, and D1 added a US jurisdiction for databases that must run and persist in the United States. Wrangler and the config packages followed with the Analytics SQL binding and graduated Basin commands, accompanied by matching support in the typed configuration package, codemods, and deploy helpers, plus a US jurisdiction for Container apps and a local Workflows createBatch API.

Elsewhere on the platform, the Workers OAuth Provider reached v1 with authorization and resource servers split across Workers and validated over a Service Binding, Monetization Gateway entered closed beta for charging agents over x402, and Logpush opened to all plans with usage-based pricing. Workers Web Crypto added ML-KEM and ML-DSA behind a compatibility flag, while Core Platform pushed out 30 days of analytics on every plan, Workers Observability data in Custom Dashboards, and self-serve Account API tokens. The workerd runtime chipped in a Cache API invalidation method and Durable Object snapshot APIs.

Security patches: Next.js, AI SDK, and the WAF

Next.js spent the week closing holes. Its current line patched a high-severity SSRF in Image Optimization alongside cache poisoning of SSG and ISR pages, cross-user content substitution, and Draft Mode content leaking into persisted pages; the 15.x line received the SSG and ISR cache poisoning fixes it was missing. The canary channel separately closed a Draft Mode leak through cross-request "use cache" deduplication and an MCP middleware DNS rebinding issue, and pinned DNS resolution when fetching external images.

The AI SDK shipped the same class of fix across two provider-utils lines: SSRF in MCP OAuth metadata discovery is closed, and DNS validation and connection pinning survive frameworks wrapping global fetch. It also gained a Topaz Labs provider.

On the edge, Cloudflare's WAF added an emergency block rule for CVE-2026-88771, an unauthenticated command execution flaw in Citrix NetScaler ADC and Gateway.

Smaller but useful

Turborepo added task tags with configuration inheritance and tag filtering in query, Cloudflare Tunnel Quick Tunnels gained email authentication, and Access learned strict service token authentication that returns 401/403 instead of redirecting to a login page. On the model side, Microsoft AI's audio models arrived on Vercel AI Gateway.

AI-generated digests may contain mistakes.
Releases covered35
Cloudflare