When the internet coughs, everyone catches a cold: why the Cloudflare outage concerns us all
On 18 November 2025, a single outage at Cloudflare made X, ChatGPT, Instagram, Canva and thousands of banking and retail sites wobble. Not an isolated incident: a real-time demonstration that our digital life rests on a handful of players.

On 18 November 2025, millions of users watched their digital services slow down, crash, or become unreachable. X, ChatGPT, Instagram, Canva, many banking and e-commerce services... all hit.
The cause? An outage at Cloudflare, a key player in the infrastructure of the global web.
A bug? An isolated incident? A run-of-the-mill technical problem?
No. A weak signal. A warning. A real-time demonstration of the systemic fragility of today's digital ecosystem.
What actually happened on 18 November 2025?
There was nothing of a cyberattack about it. According to the post-mortem published by Cloudflare, it all starts with a simple change to access rights on an internal database, deployed at 11:05 UTC. That change made a query responsible for generating a configuration file for the bot management module start returning duplicate rows. The result: the file doubled in size and went past a limit hard-coded into the software, designed for around 200 entries where sixty or so had been enough until then. The component that filters traffic could not cope with a file that big, it crashed, and it returned 5xx errors instead of the pages people had asked for.
Matthew Prince, Cloudflare's boss, summed it up bluntly: "The software had a limit on the size of the feature file that was below its doubled size." Translation: one box too small, and part of the web goes down.
The outage starts at 11:20 UTC, the bulk of traffic is flowing normally again around 14:30, and full recovery lands at 17:06. Close to six hours. Cloudflare called it its worst outage since 2019. For the length of an afternoon, logging in to X, querying ChatGPT, opening Canva or validating a payment became impossible for part of the planet, because of a file that had grown too big.
Who is Cloudflare, and why does a single outage paralyse the web?
Cloudflare is what is known as a CDN (a content delivery network), but also a security and performance provider for a huge share of websites. Put simply, it acts as a smart pipe placed between your device and the services you use: it speeds up display, filters attacks, balances load, and handles millions of requests every second.
The scale of the dependency can be measured. According to W3Techs, Cloudflare is used by 24.2% of all websites in the world, and accounts for 84.1% of the reverse proxy market. In other words, nearly one site in four goes through it, and among those that delegate this function, more than eight out of ten have picked the same provider.
That is why, when Cloudflare goes down, it is not one site that is affected, it is hundreds of thousands, directly or indirectly. The point of failure is single, and it is shared by an enormous part of the web.
What this outage really reveals
Three things, fundamentally.
First, the concentration of the web's infrastructure. We wanted to believe the internet was decentralised. In reality, it rests on a few central nodes, Cloudflare, AWS, Google Cloud, a handful of players that host, protect and orchestrate almost all of our digital life.
Second, the invisible fragility of digital services. For users, the internet works... until the day it no longer works. We get outraged, then we forget. Yet behind the apparent smoothness there are layers of infrastructure that few understand, few monitor, and even fewer control.
Third, the illusion of technical control. When a failure at an external player can freeze an entire part of your operations, you are no longer sovereign. You are the tenant of a network you do not understand, and the lease can be terminated at any moment.
And that 18 November is not an isolated accident. A month earlier, on 20 October 2025, an AWS outage in its Northern Virginia region, caused by a bug in DynamoDB's DNS system, had already brought Roblox, Fortnite, Snapchat and Duolingo to their knees. And less than three weeks after the outage of 18 November, on 5 December 2025, Cloudflare went down again. Three tremors in a few weeks, always the same pattern: a central link gives way, and millions of users pay the price.

A bug or a question of sovereignty?
No, this is not "just an outage".
It is a question of economic and strategic security. When a company, a local authority or a state depends on digital services to operate, and those services rest on single, opaque or distant providers, then sovereignty is nothing more than a word.
And cybersecurity is no longer a matter of firewalls, but a matter of mapping dependencies. Until you have listed who you rely on, you do not know what can bring you down.
How can we reduce this systemic dependency?
There is no magic solution, but there are clear directions.
- Diversify providers. Do not put all your eggs in one basket, even if it is simpler, even if it is cheaper.
- Demand transparency. The critical players of the web must publicly account for their resilience, their incidents and their continuity policies.
- Teach infrastructure, not just tools. Schools, businesses, decision-makers: it is time to understand how the web works, because you cannot protect what you do not understand.
- Take on a discourse of digital maturity. Yes, performance matters. But robustness matters more. Better a service that slows down temporarily than an entire ecosystem that collapses.

A shared responsibility
Users have the right to demand accountability. Companies have the duty to anticipate. And public authorities have the responsibility to set limits on systemic dependency.
This November outage is a small warning. Tomorrow, it could be a more serious outage, or a malicious attack. The result will be the same if we do nothing: a loss of trust, a loss of control, and a loss of resilience.
The digital world is not just a technology. It is a vital infrastructure. And like any infrastructure, it must be designed to withstand, not just to function.
The Cloudflare bug reminds us of one essential thing: a digital world without a resilience strategy is a house of cards. However powerful, connected and modern it may be.
Sources
- Cloudflare, official post-mortem of the outage of 18 November 2025: blog.cloudflare.com.
- Le Monde Informatique, "Cloudflare détaille la cause de sa panne géante du 18 novembre": lemondeinformatique.fr.
- IT-Connect, "Panne Cloudflare du 18 novembre 2025": it-connect.fr.
- Cloudflare market share (24.2% of websites, 84.1% of reverse proxies), W3Techs, July 2026: w3techs.com.
- AWS outage of 20 October 2025 (us-east-1 region, DynamoDB DNS): Wikipedia, 2025 Amazon Web Services outage.
- Cloudflare outage of 18 November and repeat outage of 5 December 2025: Wikipedia, 2025 Cloudflare outage.
Frequently asked questions
What happened during the Cloudflare outage of 18 November 2025?
An outage at Cloudflare made millions of digital services slow, unstable or unreachable for close to six hours, including X, ChatGPT, Instagram and Canva, as well as many banking and e-commerce services.
What caused the Cloudflare outage?
Neither a cyberattack nor sabotage. A change to access rights on an internal database doubled the size of a configuration file used by the bot management module. That file went past a limit hard-coded into the software, which crashed the component in charge of filtering traffic and returned error pages instead.
How long did the Cloudflare outage last?
The outage began at 11:20 UTC and was not fully resolved until 17:06, close to six hours, with a partial recovery from 14:30. Cloudflare called it its worst outage since 2019.
Why did an outage at Cloudflare have such an impact?
Cloudflare is both a CDN and a security and performance provider used by 24.2% of websites worldwide and holding 84.1% of the reverse proxy market. When it goes down, it is not one but hundreds of thousands of sites that are affected, directly or indirectly.
How is this incident a question of sovereignty and not just a bug?
When a failure at an external player can freeze an entire part of operations, the organisation is no longer sovereign: it depends on a network it neither understands nor controls. It is a matter of economic and strategic security.
How can this systemic dependency be reduced?
By diversifying providers, demanding transparency about resilience and incidents, teaching infrastructure rather than tools alone, and taking on a discourse of maturity that favours robustness over performance alone.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
