Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (30%)
- Web Tools (15%)
- Hosting (15%)
- E-mail (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 8 days ago |
|
|
Hosting | 11 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 1 month ago |
|
|
Domains | 1 month ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
TezaApps (@TezaApps) reported@idunnstudio Good catch running the audit anyway. Stripe's restricted keys are the other half of that fix, a leaked key that can only read is a bad day instead of a disaster. Mine lives only in a Cloudflare Worker so the client bundle never even sees it.
-
AntSeed (@AntSeedAI) reportedWe summarized all the replies - here are the results 👇 Why people use a gateway other than OpenRouter: • 25% Vercel AI SDK ecosystem fit • 20% Cheaper / lower fees • 13% Already in their stack (Cloudflare, LiveKit, Cursor) • 10% Direct-to-provider speed & caching • 10% Self-hosting / control • 8% Missing or slow models • 7% Privacy / data residency (ZDR) • 7% Trust & rebrand gripes Antseed resolves all of them.
-
TECHEPAGES (@techepages) reportedA newly disclosed HTTP/2 vulnerability enables unauthenticated denial-of-service attacks through memory exhaustion. By manipulating flow-control parameters attackers can force servers to buffer complete responses in memory indefinitely, leading to out-of-memory conditions. CVEs assigned: CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 Affected vendors: Apache Traffic Server, Citrix, F5 Networks, Meta, Red Hat, SUSE, Yahoo Confirmed unaffected: Cloudflare, AMD Organizations running HTTP/2 services are advised to review vendor advisories and apply patches promptly.
-
Sudotech Limited (@SudotechLimited) reportedX thought we were using a VPN. Here's what happened. MTN Nigeria uses a proxy. If you're on MTN, your traffic is automatically proxied. How we know: Logging into our Cloudflare account on Airtel always fails. On MTN, we can access Cloudflare and a few soft-banned service in Nigeria.
-
Stuxnet (@stuxnet_vt) reportedRiot literally spends millions, *millions* on infrastructure to mitigate the variability and inconsistency that comes with large scale networking. We benchmark and test things ruthlessly (as @dok2001 knows given Riot is a customer of CloudFlare). Hell, I’ve literally spent the last six years of my *life* building tooling to help test these things and it’s still nowhere near enough.
-
Jayko (@1111WRK) reportedCloudflare blocks or challenges bad requests from hitting my website. #cloudflare
-
Austin S. Lin (@siraustin) reported@prd_008 dear lord no… Sites is a fine name for what it is (it’s cloudflare pages and workers abstracted). one big issue is that you get different levels of github access from within chatgpt app depending on whether you have chat (no access to private repos), work (access to existing repos), or remote selected (full github access to create and manipulate repos).
-
Abdul Rauf (@armujahid) reported@karachism @argamingpk1 Will check. My setup is -> pihole (custom block list, dns cache) -> dnscrypt -> cloudflare zero dns. But yeah, noticed random issues on vanilla network without any custom setup.
-
Ismael Figueroa (@ifigueroap) reported@dhh @Cloudflare will it have easy (Open)VPN support?
-
Tanner Powell (@TannerPowell) reported@jackfriks @levelsio Little bit of setup involved but if you can use One Password to make a read-only folder with your env stuff, setup access token for Claude, login to wrangler (cloudflare) or vercel/supabase’s CLI tools, it really does become mostly English fast. “Explain this to me more simply.”
-
Harman (@itsharmanjot) reportedMost developers scan file extensions and call it security. Attackers don’t care what your file extension check says. There’s an open-source tool that actually scans the bytes before a file ever touches your disk. It’s called pompelmi. A TypeScript toolkit for Node.js that scans uploads in-process, MIME spoofing, ZIP bombs, nested archives, polyglot files, before storage, before your CDN spreads it, before it becomes someone else’s problem. → Scans in-process with zero outbound network calls, bytes never leave your server, no cloud API, no daemon required → Deep ZIP inspection catches nesting depth, file count, and archive traversal tricks that simple extension checks miss entirely → Optional ClamAV antivirus integration plus optional YARA rule support, for teams that want signature-based detection layered on top → Drop-in adapters for Express, Fastify, Koa, NestJS, and Next.js, plus support for Bun, Deno, and Cloudflare Workers → Built-in security scorecard grades your actual upload configuration A through F, so you know your real exposure, not just whether the tool is installed → Quarantine mode auto-moves flagged files with a sidecar JSON report, so a suspicious upload gets isolated automatically instead of silently landing in your storage bucket Any app that accepts user uploads is dealing with a real attack surface most teams treat as an afterthought. pompelmi’s whole design is catching the risk at the entry point, not after the file’s already spread across your systems. 337 GitHub stars.
-
TENJI (@ineedtendies) reportedStayed up late into the night fixing bugs and making sure launch ran as smoothly as possible. Everything was stable when I finally got some sleep, but I woke up to reports that some users are having trouble connecting to the site. We recently added Cloudflare protection to the domain, and I’m already looking into whether that’s causing the issue. I’m aware of it and working on it now. Sorry to anyone affected. Stay tuned for updates.
-
Kyle Mistele 🏴☠️ (@0xblacklight) reported@QuinnyPig @awscloud why does lambda still not support handling a single long-lived websocket connection like cloudflare workers do
-
Michał Śmiałko (@msmialko) reported@CJavierSaldana @Cloudflare you made me check @Cloudflare website - damn, they actually have a sick landing page design
-
jeli beli (@nftgamingnoob) reported@cooldown_sol @Pumpfun @Cloudflare damn
-
the Sleeping Wizard (@magicnaptime) reportedDamn guys maybe try dialing it up to 2:2:2:2 for Pete's sake @CloudflareDev @Cloudflare
-
fofotara (@fofotara) reportedCloudflare blocks or challenges bad requests from hitting my website. #cloudflare
-
Trishool | SN23 (@trishoolai) reportedAI is at the same inflection point web security hit twenty years ago. The attacks are real, the damage is mounting, and the industry is starting to realise that shipping without a safety layer isn't a risk worth taking. Cloudflare didn't create that shift in web security. It became one of the companies that defined it. We believe the same thing is happening in AI right now. AI agents have deleted production databases, exposed sensitive customer data, and taken actions their creators never intended. As AI systems do more and touch more, the cost of getting safety wrong keeps growing. The internet eventually stopped expecting every company to build its own security infrastructure because the problem outgrew what individual teams could manage. Shared infrastructure became the better answer. AI safety is heading in the same direction. That's the future we're building toward with HaloGuard on Bittensor. Production-ready, peer-reviewed, open weights, and built to protect AI systems across 46 languages, backed by a decentralised network that gets stronger every week. AI safety isn't a problem that gets solved once. It's infrastructure that has to keep learning as the threat landscape evolves. That is what we are building on Bittensor.
-
Dev Itachi (@dev_ita_chi) reported@honour_can_code Bro i just discovered cloudflare for my startup, I'm never going back.
-
Chris | Zestio (@ZestioAI) reportedDay 7: worked on our Reddit marketing pipeline today. the VPS IP is blacklisted at Cloudflare level - every request, dead. Now switching to a search-backend proxy approach instead. sometimes the problem isn't your code, it's literally your IP address 🤡
-
Rishi Raj Jain (@rishi_raj_jain_) reported@SantoshYadavDev @astrodotbuild @Cloudflare CF Pages are basically replaced with Worker. Lmk if you need any help!
-
Ekow Nyame Ayetsi (@eayetsi) reported@Cloudflare @Cloudflare The page is broken
-
Ekow Nyame Ayetsi (@eayetsi) reported@Cloudflare @Cloudflare The link is broken
-
Erik ≋ 🇺🇸 Fight for Digital Rights 🇺🇸 (@ErikInCt_) reported@PorkPoncho PlayStation can't control when AWS ***** up. Come on bro, you're smarter than this. There's no switch that says, "Bypass AWS if AWS has issues." My site goes down if Cloudflare has issues, somethings you can't control.
-
Vincent van der Meulen (@vinvan) reportedcould anyone at @Cloudflare help @mainframe get access to artifacts? working on something very cool (hopefully!) and artifacts would be *perfect*
-
loading… (@sonikudzu) reported@sevensixfive i just hope that when this happens it happens to everyone simultaneously like That Cloudflare Outage
-
Jake Gevorgian (@JakeGevorgian) reported@_slowstacking @FinancialPhys It's not like I'm not putting money in web. I spend $30k worth of time as I'm also tek savvy and do these seo stuff myself. What I've missed big time was cloudflare integration and schema. But even with that, I see companies who pop up on google first pages that I've never heard of in woodworking communities I am in... Btw, I don't think "competitor" is a valid term in this day and age for craftsmen in wood. It's not like we're selling car parts or plumbing supplies imported from China. :) this is what I'm stressing about---Google should focus on local American creators for people who look for local makers.
-
DARKMAGE4VT ♪ (@darkmage4vt) reported@DylanMcD8 Would it be a cache issue? When I moved from my hosts DNS to CloudFlare, it took a bit for it to resolve. But it works now.
-
Swamp Thing (@driftinj) reported@NateSilver538 It really blames anyone but itself. Oh that is definitely a Cloudflare problem. Gmail is definitely doing this incorrectly. Clearly, Supabase built their auth logs in correctly.
-
Honey Syed (@honeydreamss) reportedSomeone reverse-engineered how ChatGPT's web tool works and published a method for forcing it to crawl your own site. Paste a structured query into ChatGPT, it searches your domain, opens the top results, and tells you exactly what it extracted. Most companies have never done this. When they do, one of three things tends to happen. Some discover ChatGPT can't access their site at all. Their robots.txt blocks GPTBot or ChatGPT-User without anyone realizing it. The dev team or hosting provider set it up to block bots generically and caught every AI crawler in the process. Some discover ChatGPT can access the site but reads it wrong. Outdated pages, wrong product descriptions, missing pricing, content behind JavaScript that renders in a browser but looks blank to a crawler. Some discover ChatGPT reads their site fine but recommends a competitor anyway. The competitor's content is structured the way AI prefers, while theirs reads like marketing copy that sounds good to humans but gives AI nothing concrete to cite. All three scenarios are the same outcome. A business losing customers to a discovery channel they don't know exists. The deliverable is a GEO audit, Generative Engine Optimization. You audit how AI systems see, read, and cite a business's online presence and deliver a report showing what's broken and how to fix it. Five layers. Crawler access. Check robots.txt for AI crawler blocks. The most common and most fixable problem, many sites do this without knowing it. Also check server logs for AI crawler visits. If the client uses Cloudflare, the AI Crawl Metrics dashboard shows bot activity directly. Content extraction. Run the ChatGPT crawl trick, force it to search the client's domain, open top pages, report what it extracted. Also check whether content loads dynamically via client-side JavaScript. AI crawlers can't execute JavaScript the way browsers do, so dynamic content often appears blank. Brand citation audit. Ask ChatGPT, Perplexity, and Google AI Overviews: "What's the best [product type] for [use case]?" "Who are the top [service providers] in [city]?" "What are the alternatives to [competitor]?" Document whether the client is cited and who gets recommended instead. Seeing ChatGPT name a competitor while omitting them entirely is the moment a client understands why this work matters. Content structure analysis. Review key pages for AI readability. AI systems prefer direct answers in the first paragraph, specific data and statistics, headings that match how users phrase questions, and schema markup. Third-party presence. Check Reddit, review sites, and industry forums. Reddit remains one of the most heavily cited third-party sources across AI platforms, a client with no Reddit presence is missing a major signal source. Package the five layers into a report. What the problem is, why it matters for AI visibility, the specific fix. Prioritize by impact. Price at $1,500 to $3,000 depending on the size and complexity of the client's web presence. A local business with a 10-page website pays $1,500. A SaaS company with 200 pages of documentation and multiple product lines pays $3,000. Find clients on LinkedIn. "Head of Marketing," "SEO Manager," "VP of Growth," "CMO" at companies already investing in SEO. If they care about being found on Google, they'll care about being found by AI once they understand the gap. Comment OUTREACH if you want to see the exact email I would send them. Upsell the fixes. The audit is the entry point. Implementation, Updating robots.txt, restructuring content, adding schema markup, building Reddit presence, creating machine-readable FAQ pages, is a separate engagement at $3,000 to $10,000. Or a monthly retainer at $1,000 to $2,000 to continuously monitor AI citations. GEO as a category barely exists. Most SEO agencies haven't added it. Most businesses don't know it's a thing. The consultants building this practice now will set the pricing, own the case studies, and establish authority before anyone else figures out this is a service.