Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 2 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
🍄 Daemonologist 😈 (@liltechnomancer) reportedJS is bad at jobs & queues, and zero ways to keep one alive inside a DO. isolate dies, run dies with it. embarrassing. anyway I fixed it. BirdDog today. fungi week starts with the boring part everyone skipped. somebody has to save JS and it's not gonna be cloudflare
-
Ben Dickson (@bendee983) reportedShower thoughts: The compute shortage will be a lot more insane than we think, and it has much to do with AI security. Recent security incidents with AI models (Claude, GPT, Kimi, etc.) hint at where the industry will be heading. Even if you factor in the marketing and hype and hackmaxxing, the main concern is real: foundation models are becoming increasingly good at breaking into software and IT infrastructure (even when they are not instructed to do so explicitly, as with the OpenAI–Hugging Face incident). As a result, every service provider will want to deploy more security measures at the edges to prevent a potential attack from an AI model. And those additional safeguards will rely on more AI models that can detect attacks and vulnerabilities that would go undetected by heuristics-based systems. Cloudflare will use LLM-based monitoring on every incoming request, Stripe will use LLMs to monitor transactions, every company that has a sizable online platform with many users (social media, blogging, shopping) will want foundation models for security. The demand for compute will go through the roof.
-
Nifal Adam (@nifal_adam) reported@PhilcMay @a_shimanski @Cloudflare Durable objects have one big problem, its stateful. So if it gets stuck you are in for a surprise bill. So best to use it responsibly.
-
ً (@tracklim) reportedCLOUDflare… oracle CLOUD INFRASTRUCTURE… guys it’s literally in the names also remember the recent aws outages that brought down like half the internet? guess what aws is. A GLOBAL CLOUD INFRASTRUCTURE PLATFORM 😭😭😭😭
-
Jubilance - Off Record (@luftraptorAD) reported@bathotek @Raafkoning @iyici_ It’s a recent issue, the scrapper has had AI folded into it since 2024 and that’s what Cloudflare is hoping to force Google to split off from the main crawler.
-
ⓧ Jon Theory 🐍👑 Ω 7 (@Xenfluencer) reportedHTTP 402 has sat in the spec since 1997, marked reserved for future use. Cloudflare has switched it on. Anything behind their gateway can now carry a price. A page, a dataset, an API, an MCP tool call. An agent requests it, gets back 402 Payment Required with a price, pays, retries with proof. The request becomes the transaction. Stablecoins are what make that work. Card rails cannot process a third of a cent, and they assume an account and a reversal window. An agent holds a wallet, signs, settles in seconds. File crypto under speculation and you miss it. The thing unblocking the agent internet is boring programmable money that clears at sizes nobody else would bother with. The old bargain: a crawler took your content, search sent you a human, you monetised their attention. Agents break the second half. The content still creates value. The visit never arrives. An archive of 300 videos earns pre-roll on an interview from seven years ago. In an agent internet it is a tool an assistant pays a fraction of a penny to use, every time someone needs your judgement. So the question changes. It stops being how do I get more eyes on this. It becomes what do I know that a machine would pay to use. Most people will answer that late…
-
Aakash Gupta (@aakashgupta) reportedOn September 15, Cloudflare will start cutting off Google traffic for millions of its smallest customers by default. And those customers won't leave. They've been begging for this. The story starts with AI Overviews. Google began answering questions directly at the top of search, using content scraped from recipe blogs, how-to sites, and product reviewers, then sending them a fraction of the clicks. One recipe blog called the arrangement a hostage situation. Sites are looking at their traffic charts and realizing the thing they were afraid to lose is already gone. So this was never the death of the internet. This is publishers going to war with Google, and Cloudflare, which sits in front of roughly 20% of the web, just became their army. Peel back a layer and Cloudflare's move gets smarter. They aren't technically blocking Google at all. The new rule blocks any crawler that does both search indexing and AI training in one bot. Googlebot is exactly that bot, one front door for both jobs, which is why nobody could ever block the AI half without losing the search half. Cloudflare's message to Google is simple. Split the bot. Keep search separate and we'll allow it by default. Keep the bundle and our network treats you like a scraper. Which makes this a $107B company dictating terms to a $4.2T one. Cloudflare is 1/40th of Google's size, betting that controlling the pipes beats owning the index. Now we find out if David can make Goliath blink.
-
INFOSEC.WATCH (@InfosecDotWatch) reportedThe N-central story is bigger than a vulnerable management server. N-able says attackers used the legitimate Take Control feature to reach managed endpoints, then installed a Cloudflare tunnel service for persistence. RMM compromise is a downstream hunt problem.
-
Artyom Shimanski (@a_shimanski) reported@gitcommit90 @Cloudflare most people just never check what's already included
-
heather (@latentforms) reported@synopsi @Cloudflare ui is still awful, but used to be 1000x worse
-
Baraka (@zkBaraka) reported@a_shimanski @Cloudflare Have nothing bad to say about CF, it just works. I pay them about $10/m though, I do a ton of work there it makes sense. Would have been $100 elsewhere
-
ian (@sivasiann) reportedMy biggest conspiracy theory is that the US was mad that the Internet was too decentralized and hard to control that they were behind the massive rise in DDOS attacks so they can sell us the nice centralized and controllable Cloudflare as the solution to the problem they created
-
TopBotPicks (@TopBotPicks) reported@Cloudflare is my registrar. My domain cannot function because my nameservers are incorrect, and I need to change them with my registrar, according to @Cloudflare. I cannot access my business email because of this. Cloudflare cannot fix this apparently. Wtff. Never buying a domain with Cloudflare again 😐
-
Jeremy Daniele (@jdanielenj) reported@firebol226860 @signalapp @Cloudflare You're the one claiming it's hacked. It's literally on you to bring the burden of proof. That is how all arguments work. You're asking me to prove a double negative lol. My proof is what Signal publicly provides. Your proof is your tests that prove they're lying.
-
Jason Fleagle (@jjfleagle) reported@Cloudflare A 519% surge should change resilience testing. Rehearse saturation by dependency, upstream failure, control-plane isolation, degraded service priorities, communications, evidence retention, and recovery time. The useful metric is which critical service still meets its promise.