Why This Matters
What Happened
- 11:20 UTC, November 18, 2025: Cloudflare’s network began failing to deliver core network traffic. Users saw error pages indicating a failure within Cloudflare’s network.
- Not an attack: Cloudflare stated the issue was not caused, directly or indirectly, by a cyber attack or malicious activity of any kind.
- Trigger: A bot-detection database permissions change produced duplicate entries in a Bot Management feature file, roughly doubling its size. Traffic-routing proxy software hit a hardcoded size limit below that new size and failed after the oversized file had already propagated across the network.
- Blast radius: X, ChatGPT, Shopify, Canva, and Spotify went down or degraded for about five and a half hours, recovering later that afternoon UTC. Same-day video explainer.
Key Takeaways
- One provider sat under a huge share of the modern web; when it stumbled, X, ChatGPT, Shopify, Canva, and Spotify felt it together.
- Cloudflare confirmed this was not an attack — peacetime config and size-limit bugs can still cause multi-hour, multi-platform outages.
- Provider-side error pages mean your servers may be fine while customers still experience you as down.
- If dispatch, payments, reviews, and your site share one vendor path, a cloud outage becomes a same-day contractor ops outage.
- Resilience means knowing your dependencies, having a customer communication plan, and not letting one vendor own your customer-facing presence.
When the Internet Goes Down: A Small-Business Playbook
- Map dependencies. List every tool you need to take a job, get paid, or reach a customer — hosting, CDN, DNS, phone/SMS, dispatch, payments, reviews — and who runs each.
- Status page and customer comms. Decide where you post a reachable channel when the site or chat dies, and who sends that message.
- Offline fallbacks for dispatch and payments. Paper tickets, a printed phone tree, and a card or invoice path independent of primary SaaS.
- Vendor diversification. Split DNS, email, and one outbound channel so one provider cannot silence every customer-facing surface.
- Rehearse once. Drill site-unreachable booking and notify paths before a real outage.
Expert Context
November 18, 2025 showed that “the internet” is often a short list of shared providers. Cloudflare’s postmortem described a bot-management feature-file failure that hit proxy software with a hardcoded size limit — not malice, not patchable from outside. Contractors can control concentration risk: if every customer-facing surface rides the same path, provider trouble means silent phones and stalled bookings.
Keep Reading
Frequently Asked Questions
What caused the November 18, 2025 Cloudflare outage?
A change to database permissions in Cloudflare’s bot-detection systems caused duplicate entries in a Bot Management feature file, roughly doubling its size. Proxy software that routes traffic had a hardcoded size limit below that new size, so it failed after the oversized file had already propagated across the network.
Was the outage a cyberattack?
No. Cloudflare stated explicitly that the issue was not caused, directly or indirectly, by a cyber attack or malicious activity of any kind.
How long did the outage last, and what was affected?
About five and a half hours, with recovery later that afternoon UTC. Major sites went down or degraded, including X, ChatGPT, Shopify, Canva, and Spotify. Users saw error pages indicating a failure within Cloudflare’s network.
What is the “feature file” that triggered the outage?
A Bot Management data file generated from bot-detection databases and read by Cloudflare’s traffic-routing proxy. On November 18, 2025, duplicate database entries inflated it past a hardcoded proxy size limit, and the software failed.
What should a small business do when the internet itself goes down?
Map which vendors own your customer-facing presence, keep a status page or outbound message ready, and maintain offline fallbacks for dispatch and payments so one provider outage does not strand your whole operation.