CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4738

As cited

Copy frozen at (site build).

vulnerabilities

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Researchers disclosed a Spectre-based side-channel attack against Cloudflare Workers that extracted a JSON Web Token (JWT) from a co-located worker in production at up to 12 bits per second, a 360-fold improvement over a 2021 proof of concept. The attack leveraged an attacker-controlled worker to exploit transient execution vulnerabilities and leak sensitive authentication credentials from neighboring workloads.

Why it matters: Cloudflare Workers customers face exposure to credential theft through side-channel attacks when running untrusted or third-party code in shared execution environments; teams should review worker isolation policies and consider whether sensitive operations require additional protection layers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Researchers disclosed a Spectre-based side-channel attack against Cloudflare Workers that extracted a JSON Web Token (JWT) from a co-located worker in production at up to 12 bits per second, a 360-fold improvement over a 2021 proof of concept. The attack leveraged an attacker-controlled worker to exploit transient execution vulnerabilities and leak sensitive authentication credentials from neighboring workloads.

Why it matters: Cloudflare Workers customers face exposure to credential theft through side-channel attacks when running untrusted or third-party code in shared execution environments; teams should review worker isolation policies and consider whether sensitive operations require additional protection layers.

VendorsCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary