Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (35%)
- Cloud Services (26%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (9%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 14 days ago |
|
|
Hosting | 16 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Xoge (@ClassyXoge) reportedThe only self custody is complete ownership of code, node and wallet. To ensure your ip is not logged, to ensure no down server or cloudflare reroute can stop you. Be your own bank, has never been more real than madlab
-
NetAskari (@NetAskari) reportedBased on that info it quickly builds a list of over 600 python scripts and sh files starting a full chain of recon and exploit measures. It logs all its operations, success rates and outcomes. From SQL Injections, http smuggling, race condition probing, cloudflare bypass, WAF evasion, cache poisoning etc. Its attack angles are pretty wide. None of the scripts or methods seems particularly clever but if a 'fire and forget' solution is what you are looking for, than this is not too bad. 4/6
-
Dendekky (@dendekky) reported@ClaudeDevs @claudeai Loading Cloudflare in the Claude desktop browser crashes the application. pls fix.
-
2WBIA (@2WBIA_5) reported@AbuShekauGamer I don't have an issue with cloudflare
-
Milk Road AI (@MilkRoadAI) reportedNvidia just launched a security alliance with over 30 companies and OpenAI and Anthropic didn't join the party. The Open Secure AI Alliance brings together Nvidia, Microsoft, Cisco, Salesforce, Palantir, IBM, Cloudflare, CrowdStrike, Hugging Face and dozens of others to build open source cybersecurity tools specifically for AI agents. The actual trigger for this was a real incident. When Hugging Face got hit with a security breach, its closed AI security tools couldn't tell the difference between the attacker and the defenders trying to investigate so those tools blocked the forensic analysis Hugging Face needed to actually contain the intrusion. Hugging Face had to switch to an open weight Chinese model, GLM 5.2, running on its own infrastructure, to analyze more than 17,000 actions and shut down the breach. That's the case study Nvidia is using to argue closed AI security tools have a structural blind spot. If a defender can't inspect and modify the model doing the defending, they're stuck waiting on the vendor during the exact moment speed matters most. The alliance's core argument is that AI agent security depends on the entire stack like identity, permissions, guardrails, logs not just whether the underlying model's weights are open or closed. Each founding member is contributing a specific piece. Nvidia is open sourcing models and a new agent harness framework called NOOA, Hugging Face is contributing its Safetensors format to prevent remote code execution, Microsoft built a multi model bug hunting scanner, and HPE is contributing zero trust identity standards. Now, why aren't OpenAI or Anthropic in this. This entire initiative is built around open weight models and open tooling as the foundation of AI security, and OpenAI and Anthropic's core business model depends on the opposite, keeping their frontier models closed and proprietary. But to be fair there's also a competitive angle worth naming. Nvidia sells chips to everyone, so it has no downside to championing an open ecosystem where more companies build and compete on top of open models, since Nvidia gets paid on compute regardless of who wins. OpenAI and Anthropic, by contrast, are trying to build durable moats around their specific models and joining an alliance that treats open weights as inherently safer would undercut the entire pitch they make to enterprise customers about why they should pay a premium for a closed, controlled system.
-
Kashif Aziz (@kashaziz) reportedI’m using Cloudflare Email Service for @HalalCodeCheck partnership outreach. During QA, I found a flaw in my workflow: Cloudflare accepted the email, so the contact was marked “Contacted.” But accepted did not mean delivered. 1/4
-
Arda Kılıçdağı - 🦣 @arda@micro.arda.pw (@ardadev) reported@CloudflareHelp maybe you could help us. CloudFlare services in Turkey resolves @AppleSupport 's CDNs to Ukraine edge instead of Turkey, or even Greece or Bulgaria, which is closer to us. Ukraine's CDN from Turkey is throttled so hard that we get download speeds like 15 KB/sec.
-
Anjula Dwivedi (@HeyAnjula) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked.
-
RejectNova (@RejectNova1917) reported@GalliusStrados @ItsLunarArray @meaty_tw I remember a day when cloudflare didn't exist, now damn near every site i go to has their stupid verification crap
-
Bryan Jones (@bdkjones) reportedExplaining an Outage 101: @Cloudflare: "John uploaded a bad config file at 08:24:47.252 UTC. It flipped bit 0x00007FF6E4D316D0 in datacenter 49 and brought down the whole Internet. This is unacceptable. We know you count on us. John has been shot." @Apple: "Some users may have been affected by a service 'problem'. Pray we do not affect you further."
-
Josh Matz (@joshmatz) reported@prestonattebery Langchain, Mastra, and Claude Managed Agents. Vercel is close w/ Eve. Flue has Cloudflare deploys. I've thought many times to build it but the "as a service" part to me means people want to deploy on something that's not a side project. What do you want that's not these?
-
Polymarket Alpha (@Polymarketalpha) reported🚨 JUST IN: Bots now generate more web traffic than humans. According to Cloudflare, bots accounted for 57.5% of global web page requests in June 2026, while human traffic fell to 42.5%. This marks a historic turning point for the internet. AI crawlers, automated systems and intelligent agents are no longer a minor part of the web—they are becoming its dominant users. Cloudflare’s CEO had previously predicted that bot traffic would not surpass human traffic until 2027. Instead, the milestone arrived a year early. The internet is rapidly shifting from a network built primarily for humans to one increasingly accessed, indexed and operated by machines. Technological progress—or the beginning of a less human internet?
-
re:printed 3D (@reprinted3D) reported@3DInPhil @Mauker @printablescom That's because there was NOTHING wrong on my end, Phil. When I tried refreshing the page this morning, it worked. Logically, that says the problem is on either Cloudflare or Printables. Oh, and BTW, no one ever said anything about "EVIL." I know you're a big Prusa-booster, but c'mon...
-
Md. Fazley Rabby (@fazley111) reportedI’ve also checked the browser console and network requests nothing obvious (no 401/403/500 errors). Could someone from the Cloudflare team help investigate this? Thank you! 🙏
-
Shinjae Kang (@zemnanet) reportedRate-limited Wrangler deploy used to mean mash retry. 4.115.0 auto-retries Cloudflare 429s, honors Retry-After (60s cap, then fail-fast), writes retry_after_ms to WRANGLER_OUTPUT_FILE for CI. Wait duration is a handoff signal. Which owner reads it first? #cloudflare
-
The Whimsical Time Traveller. (@ObservanTimeGuy) reported@Fuckingbonehead @WG99_X @PenguySays you'd fit in at Cloudflare, you dense ****
-
Mr. Code NJ (@perpetualtalk) reported@saltyAom Does Cloudflare support bun + elyisa? Is this in the rust rewrite?
-
Cutshit (@cutshitdotnet) reported@notbrvnd0n urlscan's my first stop too 🫡 what i stack with it: resolve the redirect server-side first fetch it from a box that isn't mine, so i get the real destination without my machine ever touching the link passive recon before i open anything: domain age + TLD rep (a 25-day-old .xyz kinda answers itself) and yeah, for the Cloudflare gated ones you're right disposable Windows Sandbox, fresh instance nuked on close. never connect a wallet or sign anything in it. the drainer's almost never the page anyway it's the whatsapp/tg group one hop past it. 🦆
-
Daniel Guzman (@uTombou) reportedNow my problem. My COR connector runs on @Cloudflare Workers with McpAgent + Durable Objects. McpAgent got deprecated the same week. And that Durable Object exists to hold session state, which is the exact thing this spec removed.
-
Bobby Umar | Keynote Speaker 🇨🇦 (@raehanbobby) reportedTried so hard to contact @Cloudflare & @CloudflareHelp for some support. But it kept directing me to a website. How do I talk to a person? I have charges I don't understand, for an account I don't know about. So either I talk to you, or cancel you getting paid. #custserv #fail
-
Velko Minchev (@VelkoMinchev) reportedDay 29 📅 We had our first outage. Cloudflare ran maintenance on their infrastructure and TimerOS went down with it for a stretch. Not our code — but that hardly matters to someone who can't log in. What I care about is that everything behaved: → Incident alerts hit my inbox immediately, so I knew before anyone had to tell me → The status page reflected it live — anyone checking got a straight answer instead of a spinner → And I improved it mid-incident: incidents now open in the TimerOS support system too, so there's a written trail, not just a red dot You don't find out whether your transparency is real until something breaks. Ours held. Today: last stretch of road, heading home 🚗 Back at the desk tomorrow — Cloudflare and I have unfinished business. 😤
-
Jason Fleagle (@jjfleagle) reported@Cloudflare This is the kind of tooling that turns a privacy protocol into an operable system. The next useful artifact is a redacted debug receipt showing each hop, encapsulation step, draft version, timing, and failure boundary so teams can reproduce errors without exposing the request.
-
Grigori Karapetyan (@GregKara6) reported@weswinder no its not brother that's misinformation disseminated by a certain "competitor" hence why i call it a mind virus. i have never ran next.js anywhere but serverless, ok thats a lie but 99% of the time i have ran it serverless. and no not on vercel. i run my apps on digital ocean app platform (equivalent to serverless like lambda) and lambda itself. if you mean cloudflare workers. thats not serverless, that a totally different runtime running on v8 js engine, and by design *does not run node apps* in other words, ANYWHERE where node runs, next.js also runs with 0 modification or setup. the only thing that is vendor locked, which is the wrong thing to call it anyways is the vercel *specific* features like image optimization and SEO which is... on top of that, next.js has had the adapters api since 2019, just in case you want to go in and change the build process, but this does not matter and you probably will never ever need it.
-
Fred Rewey (@GodFadr) reported@Cloudflare - I upgraded to Pro, but it still says I can not submit a ticket (it thinks I'm still on the free version). How do I fix this?
-
Arkfile (@Arkfile_OSP) reportedThe irony. Posted a reply on this thread and got the dreaded Cloudflare Turnstile Loop thing again. { @brave / @BraveSupport please fix this! }
-
MCG (@MCGlive) reportedToday on MCG $P0 | @P0Systems w/@serpepexbt P0 is building the operating system for creators... Highlights from our second convo with Cory: 01:21 - Cory is back 03:16 - The scale claim 04:40 - @BedrockFndn incorporation 06:33 - Enables USDC staking from revenue, requires the legal structure 07:29 - They were Cloudflare's biggest gateway customer, got cut off as competition (the most postable beat) 09:00 - Why in-house GPUs? 10:24 - The China sourcing thesis 11:00 - The compute-rental vector 13:22 - Software-to-hardware shift 19:19 - "Training a model is like forking a GitHub" if you have the compute 20:41 - The Grok/xAI relationship 24:15 - Enterprise customers 31:23 - GPU depreciation/resale 35:17 - ~43K paying users (up from ~30K), ~320K active 38:41 - ~$480K MRR, ~$34K from the gateway alone 41:30 - Takeaways
-
groky (@groktuto) reportedWtf just happened is @Cloudflare down?
-
Eidzoku (@evi77ain) reportedApparently Codex Desktop 26.721.4979.0 can self-destruct just from using its built-in browser. Very agentic.💀 At first I thought Cloudflare was the cause. Nope. Perplexity reproduced the exact same failure, and it's already mentioned in one of the related issues. The actual chain is: webpage loads → Chromium GPU crashes (`101457950`) → Windows blocks the bundled `vk_swiftshader.dll` fallback for not meeting Microsoft signing requirements → GPU relaunch fails (`18`) → Codex dies.
-
ObsidianIntel 𐎡𐎼𐎠𐎴 🇮🇷 (@IntelObsidian) reported@TMobile Most importantly, why did it take half a day before you acknowledged it? Learn from Cloudflare, they go down nearly daily, but at least they are quick to announce it, then they are detailed in their after action report.
-
Evadne W. (@evadne) reportedNot very happy with @Cloudflare Workers AI so far. Previously the Kimi K2.7 endpoint would fail for some time and they wanted to close the issue after telling me to use another model. Now I have found they have not added pricing to some embedding models. Loosey goosey behaviour