1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 32% Domains (32%)
  • 28% Cloud Services (28%)
  • 16% Web Tools (16%)
  • 16% Hosting (16%)
  • 8% E-mail (8%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Paris Cloud Services 10 days ago
New York City Hosting 13 days ago
Manchester Domains 1 month ago
Angers Cloud Services 1 month ago
London Domains 2 months ago
Noida Hosting 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • migratewithmatt
    Matt Schober (@migratewithmatt) reported

    Stopping the bad guys with Cloudflare: 2,176 malicious requests blocked or challenged in the last month #cloudflare

  • GregKara6
    Grigori Karapetyan (@GregKara6) reported

    @59thProfile first of all, i think that also went over your head, my whole premise is that i have exhausted my ego and accepted llms into every part of my workflow. if i had an ego id be the other side of the argument. don't confuse me calling an llm a tool for some type of strength you have over me, that's cute and hilarious. also i don't know what's wrong with you, but my memory of our interaction is completely different, i remember mentoring you, putting you on the right track, validating your work, telling you good job, and also praising you in the cloudflare post and calling your sandbox implementations better than theirs, do you not remember that? do you not remember me teaching you about propper kernel isolation? do you not remember me putting you on the right track when you were trying to hand bake sandboxing by hand? do you not remember me telling you that if you take that approach you are making a weaker sandbox because you can never handle all the edge cases yourself? do you not remember me telling you to use microVMs instead? to me that was a positive interaction. very concerning my friend.

  • synoet
    teo (@synoet) reported

    @CherryJimbo @Cloudflare great site, wish it existed a year ago when I picked up durable objects. one more thing on DOs: the system clock is frozen except across I/O, so you can't get consistent timing or traces inside an object, making debugging perf issues basically impossible

  • Name__Groove
    Name Groove (@Name__Groove) reported

    @SpaceshipStatus Site appears down to me - cloudflare errors

  • uasneppy
    Ray 🇺🇦🏳️‍🌈 (@uasneppy) reported

    I’ll try to fix snepclub twitter embedded later today, sorry :( I didn’t know about the new updates and me having to have a burner account, plus deploying it on Cloudflare 💀

  • okdotalt
    ok.dot.alt. (@okdotalt) reported

    @FuckKoroks Every time i want to download something. Hell, even receipts are ******* blocked. **** cloudflare.

  • aberba
    aberba (@aberba) reported

    @0xRapid @dok2001 @OpenRouter The problem is Vercel provides a significantly better DX that Cloudflare and and they know it. Vercel is henceforth more expensive. Depends on what you're looking for. I use both. Wish I could use just one.

  • PrajwalTomar_
    Prajwal Tomar (@PrajwalTomar_) reported

    Vibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked. (full breakdown in my article below)

  • stefantul
    Stefan-Iulian Tesoi (@stefantul) reported

    @thdxr The biggest issue that I had with Cloudflare were the disappearing env variables. Even with wrangler secrets put command.

  • MilkRoadAI
    Milk Road AI (@MilkRoadAI) reported

    Open-source is dying and the companies that survive it are about to get very rich (Save this). That's the uncomfortable truth in Dylan Patel's take, American open source AI is basically dead. Meta has gone quiet on Llama, Mistral, once the loudest open source advocate in the West, shifted its flagship models to proprietary licensing while charging five to ten times more than comparable Chinese models for similar performance. So the only frontier level open models left are Chinese, Qwen, DeepSeek, Kimi, GLM and the labs building them barely profit from giving them away. The money instead flows downstream, to whoever hosts, serves and charges for access to those free weights. Qwen overtook Meta's Llama as the most downloaded model family on Hugging Face in 2026, and Chinese open models now out download American ones globally by a wide margin. Kimi K3 was ranked the top open source model in the world by LMArena. None of that revenue lands with the Chinese labs themselves but rather lands with the inference layer running on top. Inference is already the biggest chunk of the AI compute market, with cloud inference alone estimated near $50 billion in 2026 and growing around 60% a year, dwarfing training infrastructure spend. Token pricing has collapsed roughly a thousandfold over three years which sounds bad for margins until volume growth outpaces the price decline, keeping total inference revenue climbing. Mistral's own pivot away from open weights shows what happens when a lab tries to charge premium prices in a market Chinese competitors are commoditizing its newest model is losing on both cost and quality to rivals a fraction of the price. If Chinese labs eventually decide there's no financial reason to keep releasing frontier models for free, the open-source pipeline could dry up overnight. However, here are the publicly traded infrastructure plays positioned to benefit if open source continues to dominate. Nebius provides the same raw compute layer underneath inference demand, without needing to bet on any single model's survival. AMD is chasing that same inference chip opportunity with its MI series accelerators, positioning itself as the main alternative supplier once inference volume keeps compounding. Cloudflare (NET) benefits through its Workers AI platform, which increasingly serves as the delivery layer pushing open weight models out to edge devices and apps cheaply. Microsoft (MSFT), Amazon (AMZN), and Alphabet (GOOGL) all benefit as the hyperscalers whose cloud platforms host the bulk of enterprise inference workloads, collecting compute revenue no matter which model an enterprise ultimately runs. Milk Road Pro is tracking all the biggest beneficiaries of open source AI, if you want access to all our AI trades around this trend, you can come join us for just $1 using the link below!

  • 0xGKBRK
    Leo (@0xGKBRK) reported

    @FuckKoroks It’s not like Cloudflare puts itself in the middle by hacking the website. The person running the website wants to use Cloudflare. If you’re gonna complain to someone, complain to the website that subjects you to that crap. Or vote with your wallet and go to a normal website.

  • LewisNWatson
    Lewis N Watson (@LewisNWatson) reported

    really appreciate what cloudflare do but the chokehold they have over the internet is net negative. msft have similar issues.

  • LunchMoneyBro
    Lunch Money Bro! (@LunchMoneyBro) reported

    @scanmidgard is your website still up? Giving me cloudflare 502 errors

  • syxncwtw
    syxncwtww (@syxncwtw) reported

    Does anyone know if cloudflare is down ??

  • AymaneOnlineDev
    Aymane - أيمن (@AymaneOnlineDev) reported

    @TeeDevh You might want to check out Cloudflare Email Service. That's what I'm using. The $5/month Workers plan includes 3,000 outbound emails/month, then it's only $0.35 per extra 1,000 emails.

  • noelzappy
    Zappy (@noelzappy) reported

    app-01 and db-01 on a private local network. app-01 is the only host with a public interface, sitting behind Cloudflare. db-01 has no public route at all, it's reachable only over the LAN from app-01.

  • DFIR_Radar
    DFIR Radar (@DFIR_Radar) reported

    Chaos ransomware's msaRAT routes C2 entirely through Chrome or Edge via Chrome DevTools Protocol, making attacker traffic invisible on the wire. The RAT process never touches the network directly. - msaRAT is a Rust-based RAT attributed to the Chaos ransomware group. Initial access delivers update_ms.msi via curl over HTTP on port 443, bypassing port-based firewall rules. The MSI impersonates a Windows update and loads the RAT DLL directly into memory, leaving no obvious on-disk payload to catch. - C2 is split across two legitimate services: Cloudflare Workers at is-01-ast.ols-img-12.workers[.]dev handles SDP signaling to establish a WebRTC channel, then drops out entirely. All subsequent commands flow over a WebRTC DataChannel relayed through Twilio, so the attacker's real server IP never appears in traffic. - The RAT binds only to 127.0.0[.]1. All external traffic originates from the browser process itself, launched headless with remote debugging enabled. CSP is bypassed via a CDP command and JavaScript injected into the browser handles every network operation. What a defender sees is a browser making HTTPS calls to Cloudflare and WebRTC to Twilio, both normal. - Talos found msaRAT deployed between initial access and the Chaos encryptor, confirming it serves pre-encryption reconnaissance. Double encryption: DTLS from WebRTC plus ChaCha-Poly1305 over an ECDH-derived key means stripping DTLS still yields ciphertext. #DFIR_Radar

  • paulsd_95
    PaulSD (@paulsd_95) reported

    @thte857 @FuckKoroks You'd be mad too if your work relies on something online and that critical work got blocked because Cloudflare went down for hours. Wouldn't be surprised if lives were ruined or lost because of it.

  • igorhansachat
    Igor@hansa.chat (@igorhansachat) reported

    Turned out I broke something and my analytics was not working. The root cause was bunny[.]net (EU based cloudflare alternative) default policy was stripping some headers if "shield protect" is enabled. Good for security but breaks analytics :( Still sad as analytics is super important for me and now I have almost no data for last 4 days 🙈 Anyway, FIXED, **** happens but building is going further 😎

  • jonas
    Jonas Templestein (@jonas) reported

    @thdxr (Not a serious application) Alchemy is v good but unfortunately cloudflare is investing heavily in wrangler for local dev and it sucks not being able to run apps locally So we made a little script that takes env config and secrets in and produces wrangler files and wrangler commands It works quite well for us now - but it does feel like we are building half of IaC because we need to sequence resource creation and tear down and deal with flaky control plane APIs etc

  • aleksizy
    Alex Izydorczyk (@aleksizy) reported

    @dok2001 @Cloudflare we've been using cloudflare ai gateway. it's mostly very good. My biggest complaint I have been trying to get answers to is actually around data export/access. Any interst from someone at CF about this who is on this team? Haven't gotten far w sales/support

  • waodao_ai
    WAODAO (@waodao_ai) reported

    @Cloudflare A routing signal stops being useful once operators can rewrite it for private advantage while downstream systems still treat it as truth. Deprecation should ship with an observable replacement, or the same incentive will migrate elsewhere.

  • RyanWycuff
    Ryan Wycuff (@RyanWycuff) reported

    @unusual_whales CloudFlare is cheap as **** and normally riddled with bugs why it goes down and potential takes 1/3r the internet and source repos with it. Dont trust a thing they say.

  • SudotechLimited
    Sudotech Limited (@SudotechLimited) reported

    X thought we were using a VPN. Here's what happened. MTN Nigeria uses a proxy. If you're on MTN, your traffic is automatically proxied. How we know: Logging into our Cloudflare account on Airtel always fails. On MTN, we can access Cloudflare and a few soft-banned service in Nigeria.

  • 0xGKBRK
    Leo (@0xGKBRK) reported

    @Puftberry @FuckKoroks I’ve paid for both Cloudflare and BunnyCDN before. Both are great. But if a user complained about either of them I couldn’t shift the blame to the CDN because I put the CDN there. That’s the main issue.

  • michael_timbs
    Michael Timbs (@michael_timbs) reported

    @thdxr Hahahahha. Improbable. One of the many reasons there’s very serious applications deployed on Cloudflare. Primitives are just wrong with terrible APIs the entire way down

  • igor_kupczynski
    Igor Kupczyński (@igor_kupczynski) reported

    @dhh @jdxcode @Cloudflare maybe a "Default" or "Network Default" or similar?

  • akoskm
    Akos (@akoskm) reported

    @martindonadieu is it through the remote session? like cursor running on your mac and usng remote contorl on your phone? I'm not really into the cloud version, maybe I'm not using it properly, but it can't: - read GitHub issues from my private repos, even tho the Cursor app is installed and has permission to read them - i keep my cloudflare etc secrets locally in an .env file, cloud agent doesn't have access to that - i develop ios apps and the e2e ui tests need an actual macos running what am i doing wrong? appreciate the answer!

  • GavinKeulks
    Gavin Keulks (@GavinKeulks) reported

    @DrDavidVernon @britishlibrary Thank you for those kind words. The site was severely damaged by a server upgrade at my university, and for years I thought it was gone forever. Thankfully, repair (albeit tedious) has been possible. Now I've taken full ownership of all aspects of the site, so if it's damaged again, it will be because Cloudflare accidentally shut down the internet again (as it did a few years ago).

  • perpetualtalk
    Mr. Code NJ (@perpetualtalk) reported

    @bunjavascript Will @Cloudflare fully support bun once released?