Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 2 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
🛡️Anti IR Cyber Unit (ShKhNCU)🛡️ (@FriendOfTheInst) reportedPost-Quantum Cryptography: a deadline, not a research topic The threat is narrow and total. Shor's algorithm solves factoring and discrete log in polynomial time — that ends the dominant classical public-key families: RSA, finite-field DH/DSA, ECDH, ECDSA, EdDSA. Symmetric crypto is far less affected: known quantum speedups are much weaker — Grover's key search is only quadratic and parallelizes badly — so AES-256 and SHA-384 hold. PQC rebuilds the public-key layer on problems with no known quantum attack of comparable force. WHY NOW, WITH NO CRYPTOGRAPHICALLY RELEVANT QUANTUM COMPUTER IN EXISTENCE Harvest now, decrypt later. Vulnerable traffic captured today is readable the day a CRQC boots. Mosca's inequality: if secrecy lifetime + migration time > time to CRQC, you're already late. For 20-year secrets, waiting for evidence of a CRQC is indefensible — the migration window can close years before the machine exists. THE STANDARDS NIST finalized three in August 2024: - FIPS 203 — ML-KEM (Kyber). Lattice KEM. Your default key establishment. - FIPS 204 — ML-DSA (Dilithium). Lattice signatures. Your default signer. - FIPS 205 — SLH-DSA (SPHINCS+). Hash-based, slow, enormous — but rests on nothing but hash security. The insurance policy. Two more are coming. FN-DSA (Falcon) is not yet standardized; FIPS 206 remains in development, with floating-point Gaussian sampling making safe constant-time implementation and validation unusually difficult. HQC — selected in 2025, planned as FIPS 207 — is code-based and deliberately non-lattice, so a break in lattice math doesn't take out both KEMs. WHY THE HEDGING SIKE died in 2022 to Castryck–Decru: classical mathematics, 62 minutes on a single core of a 2013 Xeon. Rainbow fell to Beullens on a laptop. The underlying math families are old, but the specific schemes and parameter sets we're shipping have far less deployment history and accumulated scrutiny than RSA and ECC. Hence hybrids: X25519MLKEM768 in TLS 1.3 concatenates a classical and a PQ secret, designed so key establishment survives as long as one component does. Already default in Chrome and Firefox and widely deployed at Cloudflare. Signal shipped PQXDH and is rolling out SPQR, a post-quantum ratchet that combines with the Double Ratchet to form the Triple Ratchet; iMessage ships PQ3. FOR ML-KEM, THE FIRST-ORDER COST IS BYTES, NOT CYCLES ML-KEM is fast. But X25519 sends 32 bytes; ML-KEM-768 sends a 1184-byte key and a 1088-byte ciphertext. ML-DSA-65 signatures are 3309 bytes, and a chain carries several. The extra kilobytes push the ClientHello past a single packet — Chrome's 2024 Kyber rollout measured roughly 4% added median handshake latency — and PQ certificate chains get large enough to interact badly with congestion windows on lossy or high-latency links. You feel it as network latency and packetization, not CPU time. KEMS FIRST, SIGNATURES LATER For completed TLS sessions there is no harvest-now analogue: a 2035 machine cannot reach back and impersonate a server in a handshake that already finished. Long-lived signed artifacts are the harder case — code signing, firmware, notarized documents, timestamps — and that's exactly where signature migration is hardest: root CAs and roots of trust with 15-year field lifetimes. THE CLOCK Draft NIST IR 8547 — still an initial public draft, not a final standard — proposes deprecating 112-bit classical public-key schemes after 2030 and disallowing quantum-vulnerable public-key schemes after 2035. Don't read 2035 as your deadline: NIST says application-specific guidance may require earlier migration for key establishment, particularly in interactive protocols like TLS and IKE. Hybrids are accommodated as a transition mechanism, not an exemption — NIST frames them as temporary, followed by a second migration to pure PQC. CNSA 2.0 pulls national security systems in sooner. THE REAL DELIVERABLE IS CRYPTO-AGILITY Inventory what you use (CBOM), pull algorithm choice out of your protocol logic, and build assuming you swap again — because you will. And to kill a common confusion: PQC ≠ QKD. PQC is classical math on hardware you already own. QKD is a physical-layer technology needing specialized optical or satellite links, and it still requires an authenticated classical channel — so it doesn't eliminate the authentication problem.
-
Javed (@jshai0) reportedThe final result: • 27.5M+ stored OHLCV rows • 122,960 Parquet objects • 13,154 chart artifacts • Cloudflare-native daily updates • A small API read path • No provider call for every chart request We stored the data because repeated API calls were the problem. We built the API on top of our own data because predictable reads were the goal.
-
Term (@JaniBangiev) reported@schmedu_ @johnnycommits @supabase Yeah I know. As someone how is building their own startup I know there is a balance to be found here. But I think the difference for supabase becomes in the type of user they are targeting. A hobby user will probably never pay for a subscription if they can get the same thing if not better on cloudflare. So in their case the free tier does not make much sense I think.
-
Vijay Tupakula (@vijaytupakula) reported@Cloudflare Email Service is now a first-class sending provider alongside SES. Connect with a scoped token, onboard domains, publish and verify DNS records, sync quota and suppressions—and enable inbound email from the same setup.
-
Travis (@_travis_ysl) reported@bl8derunner its back up bro idk cloudflare was down
-
./ivan (@sloaxleak) reported@a_shimanski @Namecheap @Cloudflare Haha. Or just pay for a reliable email service: Google Workspace, Microsoft 365, or a Proton subscription with a custom domain. There are options. I love Cloudflare, but not everything needs to be solved by them
-
thePodKAS (@thePodKAS) reportedI have an idea 💡 You build it ✨ If it makes profit Send some to cx312.kas Here it is The first decentralized CLOUDFLARE replacement The first cheapest network ever that does the same But never shuts down like it always happens with AWS or CloudFlare Yeah Oh yeah $KAS 🍀
-
solopath (@pathlessknown) reported@HotAisle Damn nvm then maybe not meant for you haha It’ll save you money and look pretty with all cloudflare info in real time and secure too
-
Joseph Lorenzo Hall, PhD (@JoeBeOne) reportedThe archive is public, so this isn’t a “harvest now, decrypt later” use case (no secrets!). It is a useful real-world compatibility test. I’d love to see Backblaze add PQ key exchange support to B2 so Cloudflare-to-origin connections can use it without falling back to X25519. 6/6
-
Ryu-Sena (@SenaQifrey) reportedNot sure help but @cloudflare sure seem good option unless they don't pay great their security staff or it ignore adviser or PR. Good project but bad (probably) management
-
Lý Quang Tùng (@LQuangT60430837) reportedHi @Cloudflare, I'm being wrongly billed for R2 storage deleted a year ago. Opened ticket 02264237 a week ago with no reply, and my account faces suspension on 26/08. Can someone please escalate this to the support team? Thanks! PS: Past tickets were never answered either.
-
Zahid (@epiczahid47) reportedi wish cloudflare had a postgres service, thats the only thing rn thats holding me from going full cloudflare stack. sometimes d1 isn't enough. (trying to self host umami)
-
Gentra (@Gentraxyz) reported@a_shimanski @Namecheap @Cloudflare Spaceship has the same issue Their hosting is down too
-
Nicolini (@iLTardoNico) reported@heavypulp Or cloudflare will accidentally release untested code again. Never forget.
-
Philippe Martin (@PhyByte) reportedWriting the code was never the hard part. Owning what happens after it ships is. @cursor_ai bringing in a team that built agents specifically for that post-deploy loop (with real production experience from Cloudflare, Twitch, etc.) feels like one of the more grounded moves in this space with everything that happening at @SpaceXAI with @grok