Cloud Outage Analysis

Cloudflare Outage Cost - History, Timeline & Your Exposure

Updated July 2026 · 5 major incidents documented

Direct Answer

Cloudflare's most recent major outage was 18 November 2025, a roughly six-hour global failure (11:20 to 17:06 UTC). A database permissions change made a ClickHouse query return duplicate metadata, which doubled the size of the Bot Management feature file the proxy loads; it exceeded a hardcoded 200-feature limit and the reader hit a Rust panic, so Cloudflare's core proxy returned HTTP 5xx across customer sites. Before that, the 12 June 2025 outage (about 2.5 hours) knocked out Workers KV and Access when a third-party cloud provider's storage failed. Cloudflare outages tend to be global and rooted in configuration or deployment changes to the shared control and data plane rather than single-region hardware, which is why a resilient design keeps an origin fail-open path and does not make Cloudflare a single point of failure. Full chronology and SLA credit math below.

Cloudflare Outage History

DateServicesDurationImpactEst. Cost
18 Nov 2025Core CDN/proxy (5xx), Turnstile, Workers KV, Access, Dashboard, Email Security~5h 46m (11:20-17:06 UTC)Global; oversized Bot Management config file triggered a proxy panic; widespread 5xx across customer sitesNot published
12 Jun 2025Workers KV (~90% fail), Access (100% login fail), WARP, Gateway, Images, Stream, Workers AI, Turnstile, Dashboard~2h 28m (17:52-20:28 UTC)Global; Workers KV storage backed by a third-party cloud provider's outage; core proxy/DNS/WAF stayed upNot published
2-4 Nov 2023Control plane, Dashboard, API, Analytics, Logging~36 hoursFlexential PDX-04 (Oregon) power failure; configuration and visibility tools down, but the network kept serving trafficNot published
21 Jun 202219 data centers (Amsterdam, Ashburn, Frankfurt, London, Singapore, Tokyo and more)~75 min (06:27-07:42 UTC)BGP policy config change withdrew routes; the 19 sites were ~4% of the network but ~50% of requestsNot published
2 Jul 2019Global WAF / core proxy (502 errors)~27 min (13:42-14:09 UTC)A bad WAF regex caused catastrophic backtracking, spiking CPU to ~100% and dropping ~80% of trafficNot published

Cloudflare does not disclose customer impact figures and no analyst firm has published a firm insured-loss estimate for these incidents, so cost is marked "Not published" rather than guessed. Dates, durations, timestamps, and root causes are taken from Cloudflare's own public post-incident blog posts: the 18 November 2025 Bot Management incident, the 12 June 2025 Workers KV incident, the November 2023 control-plane and analytics outage (Flexential PDX-04 power failure), the 21 June 2022 BGP incident, and the 2 July 2019 WAF regex incident. Use the calculator to translate a duration like these into your own exposure. Updated July 2026.

Cloudflare SLA Credits

ElementHow it works
Uptime commitment100% uptime SLA on Business and Enterprise plans (no tiered bands)
Credit formula(Outage minutes × Affected Customer Ratio) ÷ Scheduled minutes, applied to the monthly fee for the affected service
Enterprise multiplierSuccess offerings raise the payout (commonly 10x, up to 25x on Premium)
Annual capBusiness plan: credits cannot exceed one month of fees in any 12-month period
Claim windowFile with supporting evidence within days of the incident

Per Cloudflare's published Business SLA. Full SLA credit vs actual loss analysis - credits cover only a fraction of business loss.

Frequently Asked

What caused the November 2025 Cloudflare outage?
The 18 November 2025 outage was a roughly six-hour global failure (11:20 to 17:06 UTC). A database permissions change made a ClickHouse query return duplicate column metadata, which doubled the Bot Management feature file the proxy loads. It exceeded a hardcoded 200-feature limit (normal is about 60) and the reader hit a Rust panic, so the core proxy returned HTTP 5xx. Turnstile, Workers KV, Access, the dashboard, and Email Security were affected. Cloudflare does not publish customer loss figures.
What caused the June 2025 Cloudflare outage?
The 12 June 2025 outage lasted about 2 hours 28 minutes (17:52 to 20:28 UTC). The storage behind Workers KV was partly backed by a third-party cloud provider that had an outage that same day (the widely reported 12 June 2025 Google Cloud incident). Workers KV failed roughly 90% of the time and Access saw 100% login failures, cascading to WARP, Gateway, Images, Stream, Workers AI, Turnstile, and the dashboard. Core DNS, cache, proxy, and WAF stayed up, with no data loss.
How reliable is Cloudflare?
Cloudflare sits in front of roughly a fifth of all websites (W3Techs), so even a short outage has a wide blast radius. Its failures tend to be global and rooted in configuration or deployment changes to the shared control and data plane (a bad regex, a BGP reorder, an oversized config file) rather than single-region hardware faults. Cloudflare publishes unusually detailed public post-mortems, which is why its timelines are well documented.
How do Cloudflare SLA credits work?
Business and Enterprise plans carry a 100% uptime SLA with no tiered bands. The credit is (Outage minutes x Affected Customer Ratio) / Scheduled minutes, applied to the monthly fee for the affected service. On Business, total credits cannot exceed one month of fees in any 12-month period; Enterprise success offerings raise the multiplier (commonly 10x, up to 25x on Premium). Like the hyperscalers, the credit is a fraction of your bill, not your business loss.

Updated 2026-04-27