Cloudflare error 520 means the site's own server, which Cloudflare calls the origin, answered Cloudflare with an empty, unknown or unexpected response. Cloudflare sits between you and that server, so it shows the error in place of the page. Every cause it lists sits on the site's side. The causes are a crashed server, a firewall that blocks Cloudflare, a bad HTTP/2 setup or a broken answer. The one you can sometimes clear yourself is oversized cookies. As a visitor, retry once, try a private window, and report the error with its Ray ID. Only the site owner can fix the origin.
We read Cloudflare's docs and the HTTP standards on 10 October 2026. We also checked two answers from our own server. One was the trace of our own site behind Cloudflare, and one was a 520 that did not come from Cloudflare.
What does error 520 mean?
A 520 is not a standard HTTP status code. The IANA registry, last updated in September 2025, lists 512 to 599 as unassigned, so 520 is Cloudflare's own. It belongs with 502 Bad Gateway. The HTTP standard defines 502 as a gateway or proxy getting an invalid response from the server behind it, and 520 covers an answer that was empty, unknown or unexpected.
Cloudflare's docs name the error "web server returns an unknown error". The error page carries a Ray ID, also called the cf-ray. That number is what the site owner needs to find your request in the logs.
What causes a Cloudflare 520?
These are the causes Cloudflare lists, last updated on 16 June 2026.
| Cause | Who can fix it | What to do |
|---|---|---|
| The origin server crashed or is set up wrongly, which Cloudflare says is common with some PHP apps | The site owner or host | Read the origin's error logs at the time of the error |
| A firewall or security plugin at the origin blocks Cloudflare's IP addresses | The site owner or host | Allow Cloudflare's address ranges at the origin |
| Headers over 128 KB, often from too many cookies | The visitor first, then the owner | Clear the site's cookies; the owner trims cookies and headers |
| An empty or broken answer, or missing response headers | The site owner | Make the server send a status code, headers and a body |
| HTTP/2 accepted at the origin but handled wrongly | The site owner | Fix it, or turn off HTTP/2 to Origin in Cloudflare |
| Authenticated Origin Pull switched on, but the origin is not set up for it | The site owner | Set up the origin, or switch the feature off |
The cause is not always in the origin's own logs. Cloudflare asks owners to check any load balancers, caches, proxies or firewalls between Cloudflare and the origin too.
How do I fix error 520?
If you are a visitor
- Reload once after a minute. If the server had a short failure, the page may load.
- Open the page in a private window. It starts without the site's cookies, the one listed cause you can remove. If the page loads there, clear that site's cookies in your normal window.
- Report it to the site. Cloudflare's docs say its support only helps the domain owner, and that a visitor should report the problem to the site. Send the error code, the time and timezone, the URL and the Ray ID.
People search for error 520 together with large sites such as ChatGPT and Betway. If a site like that shows it, waiting and reporting are all you can do.
If you own the site
- Read the origin's error logs at the time of the 520. Look for crashes first, since Cloudflare names PHP apps that crash the web server.
- Allow Cloudflare's IP ranges in every firewall and security plugin in front of the origin.
- Measure your headers and cookies. Cloudflare names headers over 128 KB as a cause.
- Check HTTP/2 at the origin. If the origin accepts HTTP/2 but does not handle it, Cloudflare returns 520. Turning off HTTP/2 to Origin in the Cloudflare dashboard tests this quickly.
- Compare what the origin sent with what Cloudflare served. An origin 200 that became an edge 520 was likely malformed, Cloudflare says, for example oversized headers or an early close.
- Use the workaround only to confirm. Cloudflare's temporary workaround is a DNS-only record or pausing Cloudflare, which also removes Cloudflare's protection while it lasts.
- Send Cloudflare support the evidence if the 520 continues: the full URL, the cf-ray from the error, the output of /cdn-cgi/trace, and two HAR files, one with Cloudflare on and one with it off.
How do you tell a Cloudflare 520 from any other 520?
Look at who sent it. A 520 from Cloudflare comes with the header server: cloudflare and a cf-ray header, and the error page shows the Ray ID. Any server can send the number 520 on its own, and that answer looks different.
We checked both on 10 October 2026. A test service, httpbin.org, answered our request for a 520 with an empty body. Its header said server: gunicorn/19.9.0, and it had no cf-ray. Our own site, behind Cloudflare, answered its trace page with server: cloudflare and a cf-ray header.

The trace is the text Cloudflare support asks for. A site behind Cloudflare serves it at /cdn-cgi/trace, and ours had 16 fields. One of them is your IP address, so remove it before you post the trace anywhere public.
Will a proxy or a VPN fix error 520?
No. None of the causes Cloudflare lists for error 520 involves the visitor's address. They all sit between Cloudflare and the site's own server, and only the site owner can change that link. If a 520 appears for you but not on another connection, tell the site owner. Only they can see why their server answered your request badly.
This page therefore points you to no proxy product. Our guide to error 522 through a proxy covers the rest of the Cloudflare 5xx family. For a 502 that comes from a proxy gateway, see fixing 502 Bad Gateway with a proxy.
What this page could not check
We did not produce a Cloudflare 520 ourselves, because that means breaking a site's origin. We did not touch our live site. So this page shows no real 520 page, and its parts come from Cloudflare's docs. Cloudflare does not say whether an origin's bot defense that drops connections produces 520s for some visitors. Our test was two requests on one day: one to our own site's trace and one to a test service. Cloudflare changes its docs without notice, so we will read every source here again by 10 January 2027.
Sources
- Cloudflare Docs, "Error 520", last updated 16 June 2026: developers.cloudflare.com.
- Cloudflare Docs, "Cloudflare 5xx errors", last updated 5 June 2026: developers.cloudflare.com.
- IANA, Hypertext Transfer Protocol (HTTP) Status Code Registry, last updated 15 September 2025: iana.org.
- RFC 9110, HTTP Semantics, sections 15.6 and 15.6.3, June 2022: rfc-editor.org/rfc/rfc9110.
- httpbin.org status endpoint, requested 10 October 2026: httpbin.org.
- Our own measurement: the trace of our own Cloudflare site and one 520 from a test service, 10 October 2026, logged in the research folder for this page.


