Cloudflare Workers Spectre Attack Leaks JWT

Cybersecurity researchers disclosed a remote Spectre attack against Cloudflare Workers. The exploit leaked a JSON Web Token (JWT) from a co-located Worker in a production environment at 12 bits per second. This rate was 360 times faster than a similar attack demonstrated in 2021. The end-to-end experiment used researcher-controlled attacker and victim Workers.

Severity: High · Category: Data Exfiltration

Impact: Leakage of JSON Web Tokens (JWT) from co-located Cloudflare Workers in a production environment.

Source: The Hacker News · Aug 20 2026 · Original source

What Happened

Cybersecurity researchers disclosed a remote Spectre attack targeting Cloudflare Workers. This attack was capable of leaking a JSON Web Token (JWT) from a co-located Worker within a production environment. The end-to-end experiment involved an attacker Worker and a victim Worker, both controlled by the researchers, with a JWT intentionally placed in the victim's memory. The attack achieved a leakage rate of up to 12 bits per second.

Timeline

Technical Analysis

Cloudflare Workers run code from multiple tenants in separate V8 isolates within the same operating-system process, relying on language-level isolation rather than strict process isolation to reduce startup latency. This design allows a memory read within a shared Worker process to potentially lead to cross-tenant leakage if an attacker and victim Worker are co-located in separate V8 isolates within the same Worker process.

The attack did not rely on a V8 software exploit or sandbox escape, nor did it involve native code execution. Researchers found that WebSocket communications could serve as a remote timing source, circumventing Cloudflare's restrictions on local timing sources. Additionally, Durable Objects could maintain a single Worker isolate alive for extended periods, from five to over 20 hours, allowing the attack to persist before DyPrIs could isolate suspicious scripts. WebSocket-heavy input/output (I/O) activity was observed to increase instruction translation lookaside buffer (iTLB) activity, which reduced the normalized branch-misprediction signal used by DyPrIs below its detection threshold, effectively suppressing the detection mechanism. The production tests were conducted on Linux servers utilizing AMD EPYC Zen 2 and Zen 3 processors, with measurements taken during low CPU utilization (10% to 25%) to observe optimal results, though slower attacks remained feasible under higher system loads.

Impact

The attack demonstrated the leakage of JSON Web Tokens (JWT) from co-located Cloudflare Workers in a production environment. The experiment achieved a leakage rate of up to 12 bits per second with 99.16% accuracy. This rate was significantly faster than previous demonstrations, being 360 times the rate of an earlier attack in 2021 (which achieved 2 bits per minute) and substantially higher than the 120 bits per hour reported in 2021 research. The researchers stated that no customer data was accessed during their end-to-end experiment.

Discovery & Response

Cloudflare stated that the attack had already been mitigated in production. The company improved its Dynamic Process Isolation (DyPrIs) to enhance detection capabilities, integrated the V8 Sandbox to limit transient access to 64-bit pointers, and deployed Memory Protection Keys (MPK)-based in-process isolation. The MPK-based isolation places Worker heaps behind hardware-enforced protection keys, utilizing approximately 12 available keys on modern x64 systems. Cloudflare's design combines these keys with the V8 Sandbox and a rotating memory layout to prevent nearby sandboxes from sharing a key, addressing a potential gap where random MPK assignment alone might allow two isolates to receive the same key. Cloudflare reported finding no indicators of active exploitation of this vulnerability over the three years prior to the disclosure.

How Fencio prevents this

Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.

Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.

All incidents