September 26, 2026

Massive Global Outage Hits Cloudflare: Takes Down X, ChatGPT, and Even Downdetector — “The Other Half of the Internet” Goes Dark

November 19, 2025
ModeZone

Last night, Beijing time (November 18), Cloudflare suffered a severe worldwide outage triggered by a critical vulnerability in one of its core services. The fallout was staggering — not only were major platforms like X (formerly Twitter) and ChatGPT knocked offline, but even Downdetector, the go-to site for checking outages, was affected. Netizens quickly dubbed it the perfect punchline: “Last time Amazon went down and took half the internet with it; this time Cloudflare finished the job and took the other half.”

After services were restored, Cloudflare CTO John Graham-Cumming and VP of Infrastructure Dane Knecht publicly apologized, calling the incident “unacceptable.” They explained that a routine configuration change triggered a cascading failure in the bot protection layer.

The outage began around 11:48 UTC on November 18. Cloudflare’s status page initially reported only “degraded performance on internal services,” but the issue rapidly snowballed. Users worldwide reported being unable to access thousands of websites and APIs protected by Cloudflare, while services like Cloudflare Access and WARP also became unusable. The company later confirmed the root cause was a dependency deep inside its Bot Management system.

Knecht stated:

“Cloudflare let down our customers — and the broader internet. A routine configuration change exposed a latent bug in an underlying service of our bot fight mode stack, causing it to crash and ultimately take large portions of our network and other services with it. This was not an attack.”

By 14:42 UTC, the fix was deployed, and services began recovering progressively. However, Analytics dashboards and Logs features remained unstable into the afternoon, with engineers continuing to monitor for lingering issues. As a precautionary measure, WARP access was temporarily restricted in the London region.

Cloudflare’s bot protection suite — including components like Turnstile challenges and JavaScript detections — sits directly in the traffic path of millions of sites and APIs. These systems not only block malicious bots but also validate legitimate users. When they fail, even if core CDN and DNS services remain operational, the result is widespread chaos across the internet.

According to Tom’s Hardware, this marks the third major internet infrastructure outage in the past month alone. In October, AWS US-East-1 suffered a more than 2-hour outage due to a DNS configuration error, and just days later, Microsoft experienced a large-scale Azure disruption.

These back-to-back incidents have reignited concerns about fault isolation and dependency risks at hyperscale: Can the handful of giants that power the modern internet truly contain internal failures when ~19% of all websites run on Cloudflare, ~24% of the cloud market belongs to Azure, and ~30% to AWS?

The above content is compiled by ModeZone, a fashion and entertainment magazine.

You May Also Like