What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Cloudflare’s November 18, 2025 outage was not caused by a cyberattack or DDoS campaign. An internal database-permission change caused duplicate records in a Bot Management data pipeline. The resulting feature file grew beyond a hard-coded limit in Cloudflare’s core proxy software, and its global distribution turned a bot-detection failure into widespread HTTP 500 errors.

The incident began with a database change at 11:05 UTC, affected customer traffic from about 11:28 UTC, reached its main recovery point at 14:30 UTC, and was fully restored at 17:06 UTC. Cloudflare later described it as its worst outage since 2019.

The short version: a configuration failure became a network failure

The complete failure chain was:

Database permission change
        ↓
ClickHouse query returns duplicate feature records
        ↓
Bot Management feature file grows unexpectedly
        ↓
File is generated and propagated globally
        ↓
Core proxy cannot load the file within its limit
        ↓
Bot Management module fails
        ↓
Some customer requests return HTTP 500

The memorable description—“a text file broke the Internet”—is incomplete. The important issue was not that the artifact was text-like or small. It was that a database-backed configuration artifact was trusted, automatically distributed worldwide, and read by software in a critical request-serving path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare’s incident postmortem says the event was caused by internal systems and not malicious activity.

#1 Best Overall
UGREEN Cat 8 Ethernet Cable 6FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 6FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5

What the Bot Management feature file does

Cloudflare Bot Management evaluates requests for signs of automated activity. Its public documentation describes a bot score from 1 to 99, with lower scores indicating more automated traffic. Customers can use that information in security rules, alongside signals such as JA3 and JA4 fingerprints, bot tags, and detection IDs.

The feature file is an internal model-input or classifier-configuration artifact. It packages the features used by the bot-detection system so the edge proxy can evaluate requests. Cloudflare refreshes and distributes it frequently—approximately every five minutes—because automated threats and traffic patterns change.

The public materials do not disclose the exact file format, database query, serialization process, or byte limit. Those details should not be inferred. What is established is that the file became substantially larger because of duplicate entries and exceeded a limit supported by the proxy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The trigger: a permission-management change produced duplicate data

At 11:05 UTC, Cloudflare deployed a database access-control change while updating its ClickHouse environment. A query used to generate the Bot Management feature file then returned duplicate records on some database nodes.

The permission change did not “corrupt” the database in the ordinary sense. The narrower and better-supported explanation is that it altered query behavior or data visibility, causing duplicate rows to appear in the generated output.

Because the feature file was regenerated about every five minutes, some cycles produced valid files while others produced oversized files. Cloudflare’s postmortem says the file roughly doubled in size. Independent analysis by ThousandEyes described the change as approximately 60 features growing to more than 200.

Rank #2
Jadaol Cat6/Cat6A Ethernet Cable 50FT Flat with Clips 10Gbps Network, White
  • Cat 6 performance at a Cat5e price but with higher bandwidth
  • High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
  • Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
  • UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
  • The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.

Why an optional security feature affected core web traffic

The decisive architectural problem was coupling. Bot Management was not isolated as an independent service that could fail while ordinary proxy delivery continued. Its configuration was loaded by software involved in processing customer requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When the oversized file exceeded the proxy’s hard-coded limit, the Bot Management module could not load correctly. Requests that depended on that processing path could return HTTP 500 errors. ThousandEyes observed failed responses without the normal challenge assets associated with successful bot processing, a pattern consistent with failure during Bot Management initialization rather than a normal bot challenge.

This was not a DNS outage, BGP route leak, or universal origin-server failure. Cloudflare’s edge received traffic, but some requests failed while the proxy attempted to process them.

Why the outage looked intermittent

The five-minute generation cycle and partially updated database cluster explain the changing symptoms:

  1. A healthy database node generated a valid feature file.
  2. An updated node generated a file containing duplicate records.
  3. The generated file was distributed across Cloudflare’s network.
  4. Different proxy instances loaded different versions during their refresh cycles.
  5. Requests could therefore succeed during one interval and fail during another.

As more relevant database nodes began producing the bad output, the failure became more consistently visible. This explains why repeated browser refreshes, different regions, or different edge instances could produce different results. It also made diagnosis harder: monitoring could show apparent recovery followed by renewed failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Cloudflare initially suspected a DDoS attack

The first symptoms were elevated errors and degraded Workers KV behavior, followed by fluctuating global traffic failures. A large, unstable error pattern can resemble an external traffic event, especially when the affected component belongs to a security product.

Rank #3
DbillionDa Cat 8 Ethernet Cable, 6FT 40Gbps 2000MHz RJ45 LAN Cable
  • Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
  • 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
  • F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
  • RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
  • Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.

Cloudflare initially investigated Workers KV and considered the possibility of a hyperscale DDoS attack. That was a diagnostic hypothesis, not the final cause. The real source was several layers away: an internal database change had produced a bad configuration artifact, which then failed inside the request path.

The lesson for incident responders is straightforward: a global error spike does not, by itself, identify an attack. Intermittent failures that track configuration refreshes deserve the same attention as traffic anomalies.

Incident timeline

Time, UTC Event
11:05 Database access-control change deployed.
11:28 First customer HTTP errors observed.
11:31 Automated testing detected the issue.
11:32 Manual investigation began.
11:35 Incident call created.
13:05 Bypasses implemented for Workers KV and Cloudflare Access.
13:37 Engineers focused on rolling back the Bot Management configuration.
14:24 Generation and propagation of new Bot Management files stopped; a known-good file was tested.
14:30 Main customer impact resolved after deployment of the valid file.
17:06 Downstream services fully restored.

The times come from Cloudflare’s published postmortem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How recovery worked

Cloudflare’s recovery had two essential parts:

  1. Stop propagation: engineers stopped creating and distributing new feature files at 14:24 UTC so the bad artifact could not continue replacing valid configurations.
  2. Restore a known-good state: engineers validated an earlier file and deployed it globally. Main impact was resolved at 14:30 UTC, although dependent services took longer to recover.

Workers KV and Access also received internal bypasses that allowed them to fall back to an earlier proxy version where the problem had less impact. This is why rollback was not an instant, single-step fix: the team had to identify the trigger, stop the update pipeline, validate an artifact, deploy it, and manage recovery across dependent services.

Who was affected?

The outage caused widespread failures for sites and services behind Cloudflare, but it did not affect every customer or request identically.

Exposure depended on the request path, the Cloudflare products involved, whether traffic was cached or dynamic, and how Bot Management or related services were configured. Cloudflare reported downstream impact to Workers KV and Access as well as core proxy traffic. Secondary reporting indicated that customers not using bot scores in their rules were generally less exposed, but that should not be treated as a guarantee of immunity.

Rank #4
Smolink Cat 8 Ethernet Cable, 50ft 40Gbps 2000MHz RJ45 LAN Cable
  • Cat 8 Speed, Cat 5/5e Value Enjoy Cat 8 Ethernet cable performance at a Cat 5/5e-level value. With up to 40Gbps speed and 2000MHz bandwidth, this high speed internet cable delivers more bandwidth than standard Cat 5 and Cat 5e cables, helping support smooth gaming, streaming, video calls, large file transfers and everyday wired network use.
  • 40Gbps Speed, Wide Compatibility This Cat 8 Ethernet cable supports up to 40Gbps data transfer and 2000MHz bandwidth for fast, reliable internet performance. Standard RJ45 connectors are backward compatible with Cat7, Cat6, Cat6a and Cat5e devices, including routers, modems, switches, gaming PCs, PS5, PS4, Xbox, smart TVs, laptops and printers.
  • Stable U/FTP Shielding Each of the 4 twisted pairs is individually wrapped with aluminum foil to help reduce crosstalk, noise, and signal interference. Combined with RJ45 connectors on both ends, the U/FTP design helps maintain cleaner signal transmission for a stable and reliable wired network connection.
  • Nylon Braided Durability The nylon braided jacket adds everyday durability while keeping the cable flexible and easy to route. Reinforced construction helps the cord handle bending, pulling and frequent plugging, making it a reliable choice for desks, gaming rooms, home offices and long-term network setups.
  • 50ft Reach for More Setups The 50 ft length makes it easier to connect devices across rooms, along walls, under desks or around corners. Great for router-to-PC connections, modem-to-TV setups, gaming consoles, workstations, printers and other home network equipment that needs a longer Ethernet cable.

Some cached content could continue serving while dynamic requests failed. Other customers may have seen failures only in particular applications, regions, or workflows. The outage therefore should not be described as every Cloudflare-hosted domain going offline in exactly the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The deeper failure: configuration was treated as safer than code

Cloudflare’s later “Code Orange: Fail Small” plan identified a significant process gap: software binaries had staged deployment controls, while traffic-affecting configuration could be propagated globally within seconds.

That distinction is unsafe when configuration controls the behavior of network-serving code. A generated model file can consume memory, trigger parser limits, change request decisions, or prevent a module from initializing. Operationally, it can be as consequential as a binary release.

The incident combined several weaknesses:

  • Insufficient artifact validation: a successful database query did not prove that the generated file was safe.
  • Global blast radius: the bad file could spread across the network automatically.
  • Hard-coded capacity assumptions: the proxy could not accommodate the larger file.
  • Weak failure isolation: a bot-detection component could interfere with ordinary request processing.
  • Misleading observability: downstream errors appeared before the configuration pipeline was identified.

A file can be syntactically valid yet operationally unsafe. Validation should also check size, feature counts, duplicate identifiers, schema version, required fields, numeric ranges, serialization integrity, compatibility with the proxy version, and resource consumption during loading.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Cloudflare said it would change

Cloudflare’s resilience plan focuses on three broad workstreams:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Controlled rollouts for configuration changes propagated to the network.
  • More extensive testing of failure modes in systems that handle network traffic.
  • Improved emergency “break glass” access and fewer circular dependencies during incidents.

Cloudflare also identified failures at component boundaries: the reader of the malformed or oversized configuration did not fail safely, and the downstream proxy did not sufficiently isolate Bot Management from core request processing.

Best Value
MORELECS Cat 7 Flat Ethernet Cable 6.6FT,10Gbps,Braided,Shielded(3FT-150FT)
  • [Flat Design, Zero Cable Clutter] - Lies perfectly flat against walls, under rugs, along baseboards, and through tight spaces without kinks, tangles, or messy coils. Customers praise it for effortless installation and clean cable management that blends into any room.
  • [REINFORCED BRAIDED CONSTRUCTION FOR LONG‑LASTING PERFORMANCE] - Premium cotton braided jacket paired with reinforced RJ45 connectors delivers outstanding durability, rigorously tested for over 15,000 bend cycles. Many customers describe this ethernet cable as rock‑solid and well‑crafted, ideal for long‑term daily use with no worries about premature wear‑and‑tear or connection failure
  • [10GBPS SPEED & 600MHZ BANDWIDTH — GAMING, STREAMING & FIBER READY] - Delivers 10Gbps data transfer rate with 600MHz bandwidth for PS5, Xbox, 4K streaming, and fiber internet. Customers report stable performance and fast speeds. Backward compatible with Cat 6 and Cat 5e devices
  • [STP SHIELDING & GOLD-PLATED RJ45 — MINIMIZES EMI/RFI INTERFERENCE] - 100% bare copper STP shielding helps protect signal integrity when routed near power cords. Gold-plated RJ45 connectors resist corrosion. Compatible with 2.5GB network card
  • [Works with Everything — Router, Modem, PS5, Xbox, PC, Smart TV, Printer More ] - Full backward compatibility with Cat7, Cat6, Cat6a, and Cat5e devices means this one cable works with all your home or office equipment today, and future upgrades tomorrow. Works with 10/100/1000/10G/40G BASE-T speeds. Includes 36-month warranty with free replacement support

The public announcement describes a resilience program and its workstreams. It does not prove that every remediation was complete by August 2026.

What platform operators should learn

The same failure pattern can affect CDNs, WAFs, service meshes, Kubernetes controllers, feature-flag systems, and machine-learning model pipelines. A practical checklist is:

  • Validate generated artifacts independently of the database query that produced them.
  • Reject duplicate identifiers, unexpected growth, schema changes, and incompatible versions.
  • Test parser, memory, CPU, and file-size limits before production rollout.
  • Stage changes by region, customer cohort, or percentage instead of deploying globally at once.
  • Retain and regularly verify a last-known-good configuration.
  • Provide a kill switch that does not depend on the broken control plane.
  • Define fail-open and fail-closed behavior by endpoint or traffic class.
  • Monitor independent customer-facing probes, not only internal control-plane health.
  • Keep emergency access separate from the systems being investigated.
  • Test recovery under load; a successful rollback can create a traffic surge when service returns.

The correct failure policy depends on the application. Failing open may preserve availability but allow more abuse. Failing closed may protect a login endpoint but deny legitimate users. The important requirement is that the choice is explicit, bounded, and tested.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this means for buyers of bot protection

The outage does not prove that managed bot protection should be avoided. It shows that detection accuracy is only one procurement criterion. Buyers should also ask:

  1. Are model and configuration updates staged?
  2. Can malformed artifacts be rejected before deployment?
  3. Is there a verified last-known-good version?
  4. Can bot protection fail independently of CDN and origin delivery?
  5. Can fail-open or fail-closed behavior be configured by endpoint?
  6. Are emergency controls independent of the normal control plane?
  7. Can customers route around the provider through a second CDN or alternate DNS?
  8. What status, notification, and recovery commitments are included?

Cloudflare Enterprise Bot Management is aimed at organizations needing granular bot scores, path-specific policies, analytics, and advanced signals. Pricing is sales-led rather than publicly listed in the cited documentation.

Smaller sites may need only basic protection. Cloudflare documents Bot Fight Mode for Free plans and Super Bot Fight Mode for Pro, Business, and Enterprise plans. Turnstile is another option for human verification on forms and account flows, and can be used independently of Cloudflare’s network. It is not a replacement for full bot intelligence or high-volume automated-abuse detection.

Large organizations may also compare Fastly Bot Management, Akamai Bot Manager, Imperva Advanced Bot Protection, DataDome, or HUMAN Bot Defender. The relevant comparison is not simply which product detects more bots. It is how safely each provider validates, rolls out, isolates, and reverses changes.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Conclusion

Cloudflare’s November 2025 outage was a configuration supply-chain failure inside a globally distributed proxy. A permission-management change produced duplicate database results; an automated pipeline packaged them into an oversized Bot Management file; global propagation delivered that file to edge systems; and a core proxy module could not load it safely.

The central lesson is broader than Cloudflare or bot detection: dynamic configuration deserves the same release discipline as software. If a policy, model, or feature file can influence request-serving code, it needs staged deployment, strict validation, a known-good fallback, independent monitoring, and failure isolation. Otherwise, a small internal change can acquire a global blast radius.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.