Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/1837620622/cloudflare-bypass-2026
Scripting & AutomationWeb SecurityPenetration TestingAnti-BotFingerprint SpoofingCAPTCHA Bypass
GitHub1837620622/cloudflare-bypass-2026

cloudflare-bypass-2026

Cloudflare Turnstile 绕过工具 | Cloudflare Bypass Tool based on SeleniumBase UC Mode | 支持 Mac/Windows/Linux

View Repository
41373332 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Cloudflare Bypass Tool 2026

A multi-strategy toolkit for researching and testing Cloudflare Turnstile / Challenge flows on macOS, Windows, and Linux.

面向 Cloudflare Turnstile / Challenge 的多方案研究与授权测试工具集,支持 Mac / Windows / Linux。

Python Platform License


Table of Contents / 目录

English中文
Disclaimer免责声明
Overview项目概述
Method Comparison方案对比
Features功能特性
Requirements环境要求
Installation安装
Quick Start快速开始
Usage使用说明
Python APIPython API
Proxy Format代理格式
Output输出
Project Layout项目结构
FAQ常见问题
References参考资料
Business商务合作
License许可证

Disclaimer / 免责声明

English

This project is intended for educational research and authorized automation testing only. You must comply with applicable laws and the terms of service of any target website.

  • No warranty of fitness for any particular site or environment.
  • Success rates vary with IP reputation, browser environment, target policy, and timing.
  • Datacenter IPs, true headless mode, and display-less containers typically reduce success rates.

中文

本项目仅供学习研究与已授权的自动化测试使用。使用时须遵守当地法律法规及目标站点服务条款。

  • 不对任何站点、任何环境提供通过率保证。
  • 实际效果受 IP 信誉、浏览器环境、目标策略与时机影响。
  • 机房 IP、真无头模式、无图形界面的容器环境通常会显著降低成功率。

Overview / 项目概述

English

Cloudflare defenses in 2025–2026 are layered: network reputation, TLS/HTTP fingerprinting, JavaScript challenges, Turnstile interaction, and automation-protocol signals. A single HTTP client is not sufficient for Turnstile.

This repository provides five runnable strategies plus one class-based wrapper, so you can choose the right path for single-session research, batch jobs, pure CDP control, or TLS-level reuse of an already-solved session.

Recommended baseline (open-source path):

Headed real Chrome
  + optional residential / high-quality egress IP
  + UC reconnect or pure CDP
  + OS-level captcha click when interaction is required

Not recommended as a primary Turnstile path:

True headless hard-target Managed Turnstile
Pure curl_cffi / tls-client against Turnstile
playwright-stealth alone as a “one-click” solution

中文

2025–2026 年 Cloudflare 检测已分层:网络信誉、TLS/HTTP 指纹、JS Challenge、Turnstile 交互,以及自动化协议特征。单靠 HTTP 客户端无法完成 Turnstile。

本仓库提供 5 套可运行方案 与 1 个类封装入口,覆盖单会话研究、批量任务、纯 CDP 控制,以及浏览器解出后的 TLS 层会话复用。

开源场景下更稳妥的基线:

有头真实 Chrome
  + 可选住宅或高质量出口 IP
  + UC 断连重连 或 纯 CDP
  + 需要交互时使用操作系统级点击

不建议作为 Turnstile 主路径:

真无头模式硬刚 Managed Turnstile
纯 curl_cffi / tls-client 直打 Turnstile
单独依赖 playwright-stealth 作为“一键方案”

Method Comparison / 方案对比

#ScriptStrategy / 策略TurnstileBest for / 适用场景
1bypass.pySeleniumBase UC ModeYesDefault single-session path / 默认单会话主路径
2simple_bypass.pyUC + parallel / proxy rotationYesBatch jobs; GUI click contention possible / 批量任务;并行时可能争抢系统鼠标
3bypass_nodriver.pynodriver pure CDPYesChromedriver-free CDP; needs OpenCV; AGPL-3.0 / 无 chromedriver;需 OpenCV;注意 AGPL
4bypass_curl_cffi.pyTLS fingerprint / cookie reuseNoLegacy JS Challenge or post-solve cookie reuse only / 仅旧版 Challenge 或 Cookie 复用
5bypass_cdp.pySeleniumBase CDP ModeYes2026 successor path to plain UC / UC 后继路径
—bypass_seleniumbase.pyUC class wrapperYesEmbeddable API for secondary development / 可 import 的二次开发封装

Priority guide / 选择优先级

Priority / 优先级Choice / 选择Notes / 说明
1bypass.py or bypass_cdp.pyPrimary research entry / 主入口
2bypass_nodriver.pyStrong CDP alternative; check AGPL / 强备选;注意许可证
3simple_bypass.pyThroughput / rotation; serialize GUI clicks if needed / 吞吐与轮换;GUI 点击宜串行
4Browser solve then curl_cffi reuseKeep the same UA and egress IP / 须保持 UA 与出口 IP 一致
AvoidPure HTTP against TurnstileWill not execute JS / interact / 无法执行 JS 与交互

Why curl_cffi cannot pass Turnstile / 为何 curl_cffi 无法过 Turnstile

Limitation / 限制Detail / 说明
No JS runtimeCannot complete Turnstile / modern Challenge PoW
No DOM / Web APIsMissing navigator, WebGL, canvas signals
No interactionManaged mode requires a real checkbox click
TLS is only one signalJA3/JA4 matching is not sufficient alone

Features / 功能特性

Feature / 功能Description / 说明
SeleniumBase UC ModeDriver disconnect-reconnect + OS-level captcha click
SeleniumBase CDP ModePure CDP path with reduced WebDriver attachment signals
nodriver CDPNo chromedriver; verify_cf() template click (OpenCV)
Parallel / proxy rotationBatch workers and proxy file rotation in simple_bypass.py
Timeout controlEnd-to-end timeout on primary flows
Cookie exportJSON and Netscape formats where applicable
Cross-platformmacOS, Windows, Linux (Linux needs Xvfb when headless host)

Requirements / 环境要求

Item / 项目Requirement / 要求
Python3.9+
BrowserGoogle Chrome (or Chromium on non-amd64 Linux)
DisplayHeaded GUI preferred; Linux servers: Xvfb / virtual display
OSmacOS, Windows, Linux
Optional proxyHTTP / HTTPS / SOCKS5 with working HTTPS CONNECT

Python packages are listed in requirements.txt (SeleniumBase, nodriver, curl_cffi, OpenCV headless, pyvirtualdisplay, etc.).

Python 依赖见 requirements.txt(含 SeleniumBase、nodriver、curl_cffi、OpenCV headless、pyvirtualdisplay 等)。


Installation / 安装

macOS / Windows

git clone https://github.com/1837620622/cloudflare-bypass-2026.git
cd cloudflare-bypass-2026
pip install -r requirements.txt

Install Google Chrome before running browser-based scripts.

请先安装 Google Chrome,再运行浏览器方案。

Linux (Ubuntu / Debian)

git clone https://github.com/1837620622/cloudflare-bypass-2026.git
cd cloudflare-bypass-2026
sudo bash install_linux.sh

Manual alternative / 手动安装:

sudo apt-get update
sudo apt-get install -y xvfb libglib2.0-0 libnss3 libatk1.0-0 libatk-bridge2.0-0 \
  libcups2 libdrm2 libxkbcommon0 libgbm1 libasound2
python3 -m pip install -r requirements.txt

Notes / 说明

  • Official Chrome .deb packages are primarily amd64. On ARM hosts, install a matching Chromium/Chrome build yourself.
  • 官方 Chrome deb 主要为 amd64。ARM 环境请自行准备对应架构的 Chromium/Chrome。

Quick Start / 快速开始

# Install dependencies / 安装依赖
pip install -r requirements.txt

# Method 1 — UC Mode (recommended default) / 方案1 默认推荐
python bypass.py https://example.com
python bypass.py https://example.com -p http://127.0.0.1:7890 -t 90

# Method 5 — CDP Mode / 方案5 CDP
python bypass_cdp.py https://example.com

# Method 3 — nodriver / 方案3
python bypass_nodriver.py https://example.com

Replace https://example.com with a target you are authorized to test.

请将示例 URL 替换为你有权测试的目标地址。


Usage / 使用说明

1. UC single browser — bypass.py (default)

Download Tool