The internet felt unstable this week after Cloudflare suffered its biggest outage in six years. Many popular websites froze for hours, leaving users confused and businesses scrambling. This event showed how one small change to a database can ripple across the world.
Relevant Source (Cloudflare): Cloudflare outage on November 18, 2025
Cloudflare’s official incident report details how a database permission change caused a duplicated Bot Management feature file, crashed core proxy systems, and led to the worst global outage the company has seen since 2019.
Quick Facts
- Cloudflare went down for almost six hours after a faulty database permission change.
- A duplicated feature file crashed systems and triggered 5xx errors worldwide.
- Traffic kept flipping between working and failing as servers updated at different times.
- Cloudflare says this was not a cyberattack.
- Services were fully restored by 17:06 UTC.
What Happened Inside Cloudflare’s Network
Cloudflare manages huge amounts of internet traffic, so even a small glitch can snowball into trouble. Engineers made a routine update to database permissions. The update caused the database to output duplicate data into a file used by Cloudflare’s Bot Management system. The file grew beyond its safe limit, and the system panicked.
The crash hit core services that help move web traffic safely and quickly. When the file spread across servers, it triggered 5xx errors and caused global sites to fail at random. The network kept bouncing between working and broken states every few minutes because some servers used old data while others used the new faulty version.
Key points from the incident:
- Duplicate database entries created a bloated configuration file.
- The file exceeded a strict 200 feature limit and caused software crashes.
- Rust-based modules panicked when processing the oversized file.
- Cloudflare traffic collapsed until engineers replaced the file with an older version.
Even high tech systems with smart safeguards can break when small details go wrong. Cloudflare identified the root cause quickly and restored services, showing the value of strong engineering teams during critical moments.
Relevant Source (The Register): Cloudflare broke the internet with a bad DB query
This article analyzes Cloudflare’s postmortem and explains how the ClickHouse permission change and flawed query doubled the feature file size, triggered 5xx errors, and caused intermittent global outages.
Why This Outage Matters For Everyone Online
This event hit thousands of websites and apps that depend on Cloudflare’s protection and speed. When Cloudflare goes down, huge parts of the internet slow down or stop. Many people found login pages failing, shopping carts freezing, or dashboards loading with errors. The outage reached across multiple layers of online activity.
This matters because Cloudflare handles traffic for governments, businesses, ISPs, and content platforms. A problem inside Cloudflare becomes a problem for all of us. The outage also reminded companies that depending heavily on one provider can expose them to wider risk.
Real impacts users experienced:
- Slow or blocked access to everyday websites.
- Interrupted security checks and authentication.
- Frozen dashboards and unavailable apps.
- Wide 5xx errors across global servers.
Cloudflare acknowledged the seriousness of the outage and apologized for the impact. The event underlined how important uptime is for the global internet.
Relevant Source (Atlantic Council): Critical infrastructure and the cloud: Policy for emerging risk
This report explains how heavy reliance on a small set of cloud and infrastructure providers creates systemic risk, directly supporting the point that a failure at one provider can impact users and businesses worldwide.

How The Failure Worked Behind The Scenes
Cloudflare uses a feature file to help its Bot Management system identify suspicious traffic. When the database permission change happened, it output duplicate metadata. This doubled and then tripled the file contents. The system has a hard limit of 200 features. The file jumped past that limit and crashed.
Every five minutes, servers checked the database to rebuild the feature file. Some machines had the correct version, and others had the broken one. This created a cycle of stability and failure. As the oversized file reached more machines, the network collapsed further.
Think of it like this:
- A recipe card suddenly printed the same ingredient over and over.
- The chef tried to read the giant card and dropped everything in confusion.
- Other chefs kept trying to follow the card and copied the mistake.
- The kitchen crashed until someone put the old recipe card back.
This simplified view shows how a tiny permission change ballooned into a global outage.
Relevant Source (Network World): How a bot management file push crippled Cloudflare’s global network
This analysis walks through how the ML feature configuration file for Cloudflare Bot Management is generated, refreshed every few minutes, and how the bloated file triggered repeated crashes and widespread 5xx errors.
What Users And Businesses Should Do Now
Users cannot fix Cloudflare, but they can prepare for similar events. Outages happen, even with strong systems. People and businesses can still take small steps to reduce disruption.
Action steps:
- Save important documents offline before doing online work.
- Bookmark alternate login or backup service pages when possible.
- Follow service status pages for real time updates.
- Use website monitors if you run a business or manage a site.
- Have a simple communication plan for customers during outages.
These actions help reduce stress during large outages. A little preparation goes a long way.
The main point is staying calm and having basic backups ready. Cloudflare fixed the issue quickly, and most users resumed normal activity once services came back.
Relevant Source (CISA): Cybersecurity Best Practices
CISA outlines practical steps like backups, monitoring, and planning that help individuals and organizations stay resilient during outages and other cyber disruptions.
Relevant Source (NIST): NIST SP 800-34 Contingency Planning Guide Overview
This overview of NIST’s contingency planning guidance explains how to build and maintain backup, recovery, and communication strategies to keep operations running when key services go down.
The Bigger Picture And What This Means For The Future
This outage joins a long list of cloud-related failures in 2025. Amazon faced DNS problems in October. Google Cloud felt impacts earlier this year. Cloudflare dealt with Zero Trust service issues in June. The pattern shows how complex cloud networks have become. A single point of failure can affect millions.
This event highlights the need for better safeguards and smarter testing before pushing updates. It also reminds companies to diversify their infrastructure when possible.
People rely on cloud services for daily life, work, school, and entertainment. Strong resilience and fast recovery remain critical for the future of the internet.
Final Thoughts
Cloudflare’s outage revealed how important stable cloud infrastructure is for the modern world. One small database change created a global chain reaction. Engineers brought everything back online within hours, but the incident showed how closely connected our digital systems are. Now is the time for users and businesses to stay informed, prepare for rare disruptions, and pay attention to service status reports.
FAQ
Was this outage caused by hackers?
No. Cloudflare confirmed there was no cyberattack or malicious activity involved.
Why did websites show 5xx errors?
The oversized feature file caused software crashes that blocked traffic, which produced 5xx status codes.
How long did the outage last?
Core traffic returned around 14:30 UTC and full recovery completed at 17:06 UTC.
Did this affect all Cloudflare services?
Many major services were impacted, including CDN traffic, security tools, Turnstile, Workers KV, email security, and dashboard access.
Can users prevent disruptions from Cloudflare outages?
Users cannot control Cloudflare, but they can prepare with backups, alternate workflows, and status monitoring tools.
How JENI Helps You Stay Steady During Internet Uncertainty
Online instability can feel frustrating when work depends on reliable performance. Outages like Cloudflare’s show how quickly a routine update can disrupt access across the internet. Tools that keep your own system stable and optimized become valuable when external providers stumble.
What JENI Brings To Your Daily Workflow
- Keeps your device running clean and fast so local issues do not compound cloud disruptions.
- Reduces system errors and clutter that can magnify problems during slow or unstable connections.
- Helps maintain a smooth experience even when third-party services face delays or outages.
JENI supports users by strengthening the part of the equation they can control. Local performance matters when the wider internet becomes unreliable for a few hours. A well-maintained system handles page errors, slow responses, and retries far better than a cluttered device. Stable hardware and clean software create a buffer so you can keep moving while the rest of the internet catches up.

