Cloud Outage Analysis
Cloudflare Outage Cost - History, Timeline & Your Exposure
Updated July 2026 · 5 major incidents documented
Direct Answer
Cloudflare's most recent major outage was 18 November 2025, a roughly six-hour global failure (11:20 to 17:06 UTC). A database permissions change made a ClickHouse query return duplicate metadata, which doubled the size of the Bot Management feature file the proxy loads; it exceeded a hardcoded 200-feature limit and the reader hit a Rust panic, so Cloudflare's core proxy returned HTTP 5xx across customer sites. Before that, the 12 June 2025 outage (about 2.5 hours) knocked out Workers KV and Access when a third-party cloud provider's storage failed. Cloudflare outages tend to be global and rooted in configuration or deployment changes to the shared control and data plane rather than single-region hardware, which is why a resilient design keeps an origin fail-open path and does not make Cloudflare a single point of failure. Full chronology and SLA credit math below.
Cloudflare Outage History
| Date | Services | Duration | Impact | Est. Cost |
|---|---|---|---|---|
| 18 Nov 2025 | Core CDN/proxy (5xx), Turnstile, Workers KV, Access, Dashboard, Email Security | ~5h 46m (11:20-17:06 UTC) | Global; oversized Bot Management config file triggered a proxy panic; widespread 5xx across customer sites | Not published |
| 12 Jun 2025 | Workers KV (~90% fail), Access (100% login fail), WARP, Gateway, Images, Stream, Workers AI, Turnstile, Dashboard | ~2h 28m (17:52-20:28 UTC) | Global; Workers KV storage backed by a third-party cloud provider's outage; core proxy/DNS/WAF stayed up | Not published |
| 2-4 Nov 2023 | Control plane, Dashboard, API, Analytics, Logging | ~36 hours | Flexential PDX-04 (Oregon) power failure; configuration and visibility tools down, but the network kept serving traffic | Not published |
| 21 Jun 2022 | 19 data centers (Amsterdam, Ashburn, Frankfurt, London, Singapore, Tokyo and more) | ~75 min (06:27-07:42 UTC) | BGP policy config change withdrew routes; the 19 sites were ~4% of the network but ~50% of requests | Not published |
| 2 Jul 2019 | Global WAF / core proxy (502 errors) | ~27 min (13:42-14:09 UTC) | A bad WAF regex caused catastrophic backtracking, spiking CPU to ~100% and dropping ~80% of traffic | Not published |
Cloudflare does not disclose customer impact figures and no analyst firm has published a firm insured-loss estimate for these incidents, so cost is marked "Not published" rather than guessed. Dates, durations, timestamps, and root causes are taken from Cloudflare's own public post-incident blog posts: the 18 November 2025 Bot Management incident, the 12 June 2025 Workers KV incident, the November 2023 control-plane and analytics outage (Flexential PDX-04 power failure), the 21 June 2022 BGP incident, and the 2 July 2019 WAF regex incident. Use the calculator to translate a duration like these into your own exposure. Updated July 2026.
Cloudflare SLA Credits
| Element | How it works |
|---|---|
| Uptime commitment | 100% uptime SLA on Business and Enterprise plans (no tiered bands) |
| Credit formula | (Outage minutes × Affected Customer Ratio) ÷ Scheduled minutes, applied to the monthly fee for the affected service |
| Enterprise multiplier | Success offerings raise the payout (commonly 10x, up to 25x on Premium) |
| Annual cap | Business plan: credits cannot exceed one month of fees in any 12-month period |
| Claim window | File with supporting evidence within days of the incident |
Per Cloudflare's published Business SLA. Full SLA credit vs actual loss analysis - credits cover only a fraction of business loss.