1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 43% Cloud Services (43%)
  • 21% Domains (21%)
  • 14% Web Tools (14%)
  • 14% Hosting (14%)
  • 7% E-mail (7%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 18 days ago
Los Angeles Cloud Services 19 days ago
Paris Cloud Services 1 month ago
New York City Hosting 1 month ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • srmanuelangel
    Manuel Suarez (@srmanuelangel) reported

    I think infra might be one of the areas where coding agents feel the most unfair. So much of the job used to be babysitting slow feedback loops: change something → deploy → wait 15 min → find out it broke → fix → wait again. Now you can give an agent the Terraform, let it understand how the whole thing is wired together, read the errors, and keep iterating. Obviously this doesn't make infra trivial. Security, WAFs, rate limits, CloudFront, Cloudflare, permissions, etc. still need actual thought. But for relatively simple products, the amount of annoying work that just disappeared is kind of insane. It also makes some infra SaaS feel a lot less essential when you have an agent + a pile of AWS/GCP/Azure startup credits. Much respect to the people who were doing all this **** manually 5 years ago.

  • copium9000
    Copium (@copium9000) reported

    @kodyfy @juiceboy_of_abj DNS solves connection issue. DNS doesn't solve the Cloudflare login page issue. You'd need a proxy for that. To think we have an NCC in this country 🤦🤦

  • guard_if
    Mike Choi (@guard_if) reported

    if you want to run a series A startup: Rails = the entire app. Postgres = source of truth. ClickHouse = analytics. Kafka = getting one into the other. (MSK) Sidekiq = everything async. ECS + EKS = deploys your own models. (GPUs, lol) Terraform = all of it, in code. Grafana + Sentry = knowing what broke. Statsig = flags + experiments. Stripe = money in. Mercury = money out. Loops = email. Intercom = support. Cloudflare = DNS. Vercel = marketing website. Linear + Graphite = shipping. Claude = coding / artifact generation total monthly cost: definitely not $20.

  • q_huy_ngo
    Quoc Huy (@q_huy_ngo) reported

    @threepointone @jpschroeder Sorry to jump into this thread, but I'm in almost the same situation. A looped Durable Object left me with a $655.83 bill. My case has had no reply for 25 days, and Cloudflare says my services will be downgraded Aug 21. Could you help surface case 02252354 too?

  • yenkel
    yenkel (@yenkel) reported

    @jfroma @vercel @Cloudflare railway is v popular it seems. any reliability issues?

  • ahmetdotrun
    Ahmet (@ahmetdotrun) reported

    two things i've been experimenting with over the last couple of days: 1) kitesurf by @Cloudflare free while in beta. i'm looking at it for (scaled) agentic offensive security work: let an agent explore an app, understand it, map the attack surface. browsers are expensive to run, hard to scale. it seems a lighter option on CF's edge, so potentially a cost effective one for me. tho, bot challenges are still a problem. 2) grok build by @SpaceXAI first time giving grok 4.6 a proper shot. faster than other frontiers and more capable than i expected. burns through the limits quicker than i'd like though.

  • sinasanm
    Sina Meraji (@sinasanm) reported

    changelog v0.98.0: replaced the onboarding (which previously required you to manually type in your Cloudflare account ID and create an API key and select permissions one by one) with "login with Cloudflare," which creates the API key and selects the right permission for you. a few steps less to get started. npm i -g kimiflare

  • mynameistito
    Tito (@mynameistito) reported

    Adding on to this, I'm pretty sure you'd even be able to fully host a game server on the Cloudflare network exclusively with workers/containers, with a contain working as a TURN switch for UDP traffic... Although, it wouldn't be feasible, might try have a play w/ this lata!

  • 101xanshu
    Anshu (@101xanshu) reported

    Dear @Cloudflare, hire me. I have a growing list of Wrangler issues on Windows/WSL that I'd very much like to fight professionally 😭

  • cyber39glt
    R𝐞𝐦𝐢 | C𝐲𝐛𝐞𝐫ɢʟᴛ (@cyber39glt) reported

    Most likely an IP routing/peering or Cloudflare security issue. It doesn’t necessarily mean Airtel is blocking Cloudflare. The specific IP range Airtel assigns (sometimes through CGNAT/shared IPs) could be having issues reaching Cloudflare.

  • valhalla_dev
    developing valhalla (@valhalla_dev) reported

    Notably, most technology that has been lifechanging and revolutionary is technology that the average person does not at all care about. The average person doesn't care about Linux, or Docker, or the HTTP protocol, or virtual hosting, or React. They don't have to. They like what comes downstream of that technological progress. So the argument that "AI doesn't matter to most people" is moot, because the downstream effects of AI do matter. Yes, AI People need to stop pretending like AI is going to steal everyone's jobs yesterday, yes they need to stop shoehorning AI into places that don't matter. But the answer to "why should the average person give a damn about AI" is generally "they probably shouldn't." The market is going to get kinda crazy, there is going to be a lot of tumult around data centers and inference buildout, and a lot of new consumer facing and business facing tech is going to be released at an accelerating rate. But the average person shouldn't really have to care about AI, any more than they care about what a VPS is or how CloudFlare Pages work.

  • ptaranat
    Panat (@ptaranat) reported

    @HotAisle @offerexpired you’re telling me in your 30 years of infra, you never ran into a situation so dire you had to run the CI/CD pipeline off a company laptop to push a hotfix to ****? i’ve had to do this twice now, usually when multiple AWS regions are down or cloudflare is having a major outtage and the CI/CD was in the same infra as **** and no one bothered to do region/provider failover for internal tools until after the post-mortem. imagine a situation so bad you couldn’t even rollback. it’s not something you do day to day, but it immediately exposes gaps.

  • ryan_builds_
    Ryan — building Eazip (@ryan_builds_) reported

    Video transcoding is expensive. AWS MediaConvert → too expensive FFmpeg on Fargate Spot → 30% cheaper, still expensive Considering Cloudflare Stream: upload → encode → download MP4 → delete Has anyone used Stream as a temporary transcoder? Smart shortcut or bad idea? 👀

  • royce_james
    Royce (@royce_james) reported

    @grok @bot is having issues connecting to some webpages. For instance: Grok Bot can browse Disneyland and see plans, but the Reserve page 404s before the guest picker. Root cause: the sandbox runs on a Cloudflare datacenter IP. Sites treat those like bots, so booking SPAs fail while the rest of the site loads. Phone on home Wi-Fi books the same dates with no issue. Classic residential-IP requirement. Any chance we can get Grok a residential proxy / home IP for these flows?

  • shydev69
    shydev (@shydev69) reported

    biggest tech bubble that has burst in the last 6 months - cloudflare has poor ui/ux compared to vercel

  • gagansuie
    Gagan Suie (@gagansuie) reported

    104 resolve the proxy hostname over DNS-over-HTTPS through Cloudflare or Google, so no plaintext DNS query appears on your network. The advertised premium servers in JP, SG, CA, AU and TR returned no A record. They do not exist.

  • _ctoxyz
    ctoxyz (@_ctoxyz) reported

    @cloudflare literally just PREVENTED that company from getting a SALE from me. nice work **** HEADS

  • MangoOS_Network
    Mango Network (@MangoOS_Network) reported

    AI agents are moving from chat to payments. Cloudflare is testing agent wallets. Circle is building USDC-based agent payment infra. Apps are preparing for software that can hold value and transact onchain. But agents cannot scale across broken routes, isolated VMs and fragmented liquidity. That is why multi-VM, omnichain infrastructure matters. @MangoOS_Network is building in that direction with OPStack, Move, EVM and MoveVM support. The best rails are the ones users and agents barely notice.

  • sinasanm
    Sina Meraji (@sinasanm) reported

    update: now when github is down, your CI/CD still runs on your Cloudflare account as long as you've initiated gitflare. when gitHub is back, the branch is pushed back to it automatically (fast-forward only, never force).

  • CapyToolkit
    CapyToolkit (@CapyToolkit) reported

    @mdanassaif @spaceship Jump to Cloudflare! At least we all will be on the same boat when it's down... 🤪

  • AISUEDE
    Suede Labs (@AISUEDE) reported

    @Cloudflare We ran 38 buyer prompts across three engines against our own products and published the losses. Crawler access was the cheap fix. The expensive lesson: answers named entities with deep third-party records, not the best pages. Measurement first is the right call.

  • OriginalOGDAW
    The Civic Lens (@OriginalOGDAW) reported

    @TorBox It people knew they could just use free cloudflare and make there own Debrid service for free with 10tb monthly limit

  • rea1ReinaCruz
    Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported

    @Cloudflare Please, fix human verification

  • FLINTKYA
    FLINT (@FLINTKYA) reported

    So the firewall blocked the attacker, and then an AI agent finished the attack for them? That is the security problem behind Ghostjacking, an AI agent hijacking technique demonstrated by Tenet Security across Cloudflare, Datadog, and Sentry. Ghostjacking is an attack in which adversaries poison the logs, alerts, telemetry, or other operational data AI agents consume. Instead of compromising the agent directly, the attacker manipulates information the agent already trusts, then relies on the agent’s legitimate permissions to complete the attack. In @tenetsecurity's Cloudflare demonstration, the malicious request was actually blocked. The attacker received a 403, exactly what you would expect from a functioning security control. But attacker-controlled data from that request entered telemetry that an AI coding agent later reviewed. The agent interpreted the poisoned data as trustworthy context and used its own authorized access to modify DNS records. Tenet reported the technique succeeded 9 out of 10 times against Claude Code in its tested configuration. In other words, the firewall worked. The trust model, not so much. How Ghostjacking works: 1. An attacker submits malicious input. 2. A security system blocks or records it. 3. The attacker-controlled content enters logs, alerts, or telemetry. 4. An AI agent consumes that data during a legitimate workflow. 5. The agent acts on the poisoned context using its real permissions. The Datadog and Sentry demonstrations push the idea further. Poisoned telemetry can lead agents toward code execution, credential exposure, infrastructure changes, and even agent-to-agent lateral movement, where one compromised decision influences another agent downstream. That creates a problem traditional IAM was never designed to solve. An AI agent can be properly authenticated, use valid credentials, operate within its authorized permissions, and still execute an attacker’s intent. That distinction matters to us as AI agents gain authority over payments, infrastructure, purchasing, customer accounts, and other real-world actions.

  • FroidEtCold
    NorthernChuck (@FroidEtCold) reported

    Ported Buzz from Rust to C and called it Hush. Changed the User Interface around and started bolting on pieces. Built using @tetsuoai's writing legible C skill. Included a STUN/TURN server in C as well. The idea being that you can deploy this thing and use it to pin down media paths and enable voice/video. Will be adding support for Cloudflare TURN, eventually

  • CapyToolkit
    CapyToolkit (@CapyToolkit) reported

    @h_meow_meow @TeeDevh Actually these cause 2 separate issues. Crawler Hints with Cloudflare caching made thousands of unnecessary URLs to be submitted via IndexNow. Bot Fight mode was blocking legitimate Bingbot and OpenAI IPs (not detecting them as Verified).

  • s41r4j
    S41R4J (@s41r4j) reported

    I recently ran into an interesting Cloudflare Turnstile issue while looking at abuse hitting my own domain/server! One thing that surprised me: The Turnstile sitekey is public by design! That does NOT mean someone can directly bypass Turnstile just by having the sitekey; But this is where it gets interesting! An attacker can take: `your domain + your Turnstile sitekey` and feed it into CAPTCHA-solving infrastructure to obtain a real, valid Turnstile token! So the flow can effectively become: sitekey → automated solver → valid token → protected endpoint The attacker is not breaking Cloudflare, they are simply solving the challenge at scale! "Which means Turnstile should never be treated as the entire security layer!" Your backend should still: • Verify every token using Siteverify • Validate the hostname • Validate the expected action • Restrict allowed hostnames • Rate-limit the actual endpoint • Add abuse detection around sensitive actions CAPTCHA ≠ authorization!!! And a public sitekey ≠ a secret! A small implementation detail, but a pretty important distinction when building abuse-resistant systems!

  • cyrusradfar
    Cyrus Radfar (@cyrusradfar) reported

    @ravikiran_dev7 the lack of any protections for customers from a company at the scale of Cloudflare is their mistake. Rate limits, rational max/scaling rules that would need to be manually overridden by the customer with understanding of the scale they expect. I'm thankful they recognized this is their mistake and they made things right.

  • wyattjoh
    Wyatt Johnson (@wyattjoh) reported

    @rough__sea Have a private fork of celld adding support for durable Cloudflare Agents SDK and AI chat with isolated Code Mode execution. Think it's too big to merge into celld, but it's been fun experimenting with it!

  • yenkel
    yenkel (@yenkel) reported

    @positiveblue2 @vercel @Cloudflare any issues with reliability?