Major outages and post-mortemsBackground
Cloudflare outage on November 18, 2025 takes down sites and Access logins for hours
From 11:20 to 17:06 UTC (6:20 a.m. to 12:06 p.m. EST) on November 18, 2025, Cloudflare’s core network returned errors for many sites it serves. Cloudflare said a database permissions change doubled the size of a Bot Management feature file, which crashed the software that routes traffic. Cloudflare Access, which some employers use for remote logins, was among the affected products. Published October 6, 2026.
- Event date
- Published here
- Updated
- Source
- Cloudflare blog
Background itemThis happened 322 days before we published it (more than 90). It is here as context for the guides it links, not as breaking news. Check the source for anything that has changed since.
What changed
On November 18, 2025, Cloudflare had a major outage. Cloudflare sits in front of a large share of websites and apps, so when its core network failed, many unrelated sites returned errors at once.
Cloudflare’s post-mortem explains what happened. A change to one database system’s permissions caused it to output duplicate entries into a “feature file” used by Cloudflare’s Bot Management system. That file doubled in size and was pushed to every machine in Cloudflare’s network. The software that routes traffic had a size limit below the new file’s size, so it failed. Cloudflare said it first suspected a large attack, which slowed the diagnosis.
Products listed as affected include Cloudflare’s core CDN and security services, Turnstile (the check box some login pages use), Workers KV, the dashboard, email security and Cloudflare Access, which some employers use to let staff reach internal apps remotely.
Cloudflare wrote: “An outage like today is unacceptable.”
When
- Start: 11:20 UTC on November 18, 2025 (6:20 a.m. EST).
- End of impact: 17:06 UTC (12:06 p.m. EST).
- That is almost six hours, covering the US East Coast morning.
Who is affected and what it means for you
Anyone visiting a site that uses Cloudflare could have seen errors, whatever connection they were on. Remote workers whose company uses Cloudflare Access may have been unable to reach internal tools, which looks a lot like a VPN failure.
For a Starlink user, the risk is chasing the wrong problem. CGNAT really does break some VPN types, so it is tempting to blame it. But on November 18 the problem was at Cloudflare. Our VPN guide explains which VPN failures CGNAT actually causes, so you can rule them in or out.
A backup internet line would not have helped, because both paths lead to the same failed service.
What you can do now
- When many sites fail with similar error pages, check Cloudflare’s status page before troubleshooting your connection.
- Check your link in the Starlink app. No outages and normal latency mean the problem is upstream.
- If your company uses Cloudflare Access or WARP, ask IT what the fallback is when Cloudflare is down, if there is one.
- Our troubleshooting page covers the failures that are on your side.
What stays the same
- Starlink’s network was not involved.
- The fix for this kind of outage is on the provider’s side; there was no setting to change at home.
What we don’t know yet
- Cloudflare didn’t give a count of affected sites or users.
- Cloudflare announced a resilience plan in December 2025 (linked below); we haven’t seen independent data on whether it has reduced outages.
- We have no logged data from November 2025.
This item is background: it happened more than 90 days before we published this page.
Source
Related guides on this site
Correction log
No corrections since publication. Spotted an error? See corrections for how to tell us; changes are logged here with the date.