
Credits: BalticServers.com / Wikimedia Commons — CC BY-SA 3.0.
On November 18, 2025, a Cloudflare outage slowed or cut off access to many services. It affected France and the entire world, from social networks to generative AI. The company identified a Cloudflare traffic spike at 12:20 PM, causing a chain of errors. Then, a gradual Cloudflare recovery took place in the afternoon. The investigation is ongoing, along with questions about the web’s dependence.
What Happened On November 18, 2025
Shortly before 12:30 PM (Paris time), Cloudflare reported a Cloudflare incident on its global network. At 12:48 PM, the company said it was investigating “an issue affecting multiple customers.” Around 1:21 PM, a partial recovery was observed, but errors persisted. At 2:13 PM, other features were restored. In the afternoon, Cloudflare deployed a fix, then announced gradual stabilization. Later, a return to normal was observed at the end of the day. In addition, they are monitoring the infrastructure and promise a post-incident report.
In the meantime, a global web outage paralyzes entire sections of the Internet: slow pages, errors, and unavailable sites multiply. Millions of users describe matching symptoms: on some AI services, a message appears — “Please unblock challenges.cloudflare.com to proceed” — and mobile access can sometimes work around the blocks encountered on desktop.
Condensed Timeline
- 12:20 PM: Cloudflare traffic spike at 12:20 PM observed by Cloudflare on one of its services.
- 12:48 PM: first status message; investigation ongoing.
- 1:21 PM: gradual Cloudflare recovery with error rates still high.
- 2:13 PM: more features restored; fixes underway.
- Late afternoon: widespread fix, reinforced monitoring, and gradual normalization.
Key point: the exact origin of the traffic spike remains uncertain at the time of the first public statements. The company refers to a Cloudflare incident, without attributing it to a single cause.
Why A Cloudflare Outage Knocks So Many Services Offline
Cloudflare is an infrastructure player that provides CDN, DDoS protection, web application firewall, and DNS services to millions of websites. In practical terms, a large share of traffic passes through its points of presence before reaching publishers’ servers. On average, the network routes about 81 million HTTP requests per second: a volume that explains, through simple leverage, the scale of the impact when one link breaks down.
Add a structural factor: nearly 20% of sites use it as a reverse proxy to speed up display and filter unwanted traffic. The concentration of critical functions among a few operators, such as Cloudflare, creates systemic dependence. In addition, other CDNs and cloud providers also contribute to this dependence. When one coughs, entire ecosystems catch cold.
Affected Services: From AI To Social Media
The outage disrupted major platforms, such as X (formerly Twitter), causing significant interruptions. In addition, generative AI services, such as OpenAI, were affected. Furthermore, ChatGPT down cloudflare and Claude experienced notable disruptions. In addition, news sites — including Ecostylia Magazine — and entertainment platforms, including Spotify, were also affected. Finally, creation tools, such as Canva, encountered malfunctions. In addition, online games, like League of Legends, were also affected. Even incident-tracking services like Downdetector showed anomalies, a sign of a domino effect on the observation ecosystem itself.
The exact scope varies by region and use case: some publishers with recovery plans, multi-CDN redundancies, or alternative routes maintained limited degradation. Others, heavily integrated into the Cloudflare chain, suffered full interruptions.
What We Know About The Cause — And What We Still Don’t Know
At the heart of the incident, Cloudflare reported an unusual surge in traffic affecting a service on its network. As a result, this caused cascading errors for some customers. In the first hours, caution prevails: no hasty attribution to a cyberattack or a third-party provider. The company speaks of a Cloudflare incident, identifies the problem, then deploys an emergency fix. A post-mortem investigation will detail the chain of events, the lessons learned, and any preventive measures.
This delay between symptom, diagnosis, and public explanation is normal at this scale: teams must stabilize before they tell the story. In a network handling tens of millions of requests per second, an apparently minor change can have consequences. In fact, it can produce nonlinear effects.
A Revealer Of Digital Weak Points
This outage highlights a blind spot in today’s digital world. In fact, essential services (news, payments, messaging, games, professional tools) rely on private building blocks. In addition, their mechanisms are not very visible to the general public. The sovereignty and resilience of the Internet do not depend only on access networks. In fact, they also play out in these intermediation layers that optimize and secure traffic.
Three issues stand out:
- Redundancy: encourage multi-CDN architectures, alternative DNS routes, and tested business continuity plans.
- Transparency: publish detailed and comparable post-mortems to build a shared feedback loop.
- Public interest: treating these infrastructure platforms as essential connectivity goods is crucial. They must meet availability, eco-design, and frugality requirements. Avoid mass refreshes during an incident, because they worsen the load.
Understanding: CDN, DDoS, “Traffic Spike”
- CDN (content delivery network): a global network of distributed servers that bring content closer to users to speed up display and absorb spikes.
- DDoS protection: mechanisms that filter malicious requests sent in bursts to overload a service. Imperfect filtering or a sensitive configuration can degrade legitimate traffic.
- Traffic spike: a sudden increase, whether expected (launch, breaking news) or unexpected, can exceed thresholds and cause queues, latency, and errors.
Best Practices For Users
- Check official status pages: the Cloudflare Status page and service status pages provide chronological updates.
- Switch devices or networks: if the web on desktop is blocked, trying mobile (or vice versa) may restore access.
- Limit refreshes: avoid constant F5ing and repeated downloads that increase the load.
- Distinguish local/global outages: test other sites, a different DNS, or a guest network to isolate the problem.
- Delay sensitive actions: during instability, postpone payments, critical updates, or configuration changes.
Best Practices For Publishers
- Tested business continuity plan (BCP/DRP) with multi-hosting and multi-CDN.
- Instrumentation: logs, telemetry, and alerts independent of the main provider.
- Careful deployments: change reviews, canaries, quick rollbacks.
- Communication: clear, time-stamped updates to reduce uncertainty for users.
What The Public Interest Reveals
Beyond technology, the incident affects access to information, service continuity, and trust. Public authorities as well as companies have an interest in mapping their dependencies and funding alternatives or capacity reserves. Resilience designed collectively — open standards, interoperability, incident publication requirements — reduces the collective risk surface.
What Is Still Expected
- A post-mortem detailing the root cause and the added safeguards.
- A sector-wide retrospective on dependency chains and ways to limit their spillover effects.
- Possible recommendations to certify or audit infrastructure operators with high systemic impact.