Researchers Use Remote Spectre Attack to Leak JWT From Cloudflare Worker

Researchers used a remote Spectre attack to leak a JWT between co-located Cloudflare Workers. Cloudflare says the technique is now mitigated.

Written By
KJ
Kezia Jungco
Aug 20, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A remote Spectre attack successfully pulled a JWT from a co-located Cloudflare Worker, showing how CPU side channels can reach across tenant boundaries in shared serverless environments.

Researchers extracted the deliberately planted token at up to 12 bits per second in Cloudflare’s production environment. The research team controlled both Workers and deliberately placed the token in the victim. Cloudflare said it found no indicators that the technique had been actively exploited and has mitigated the demonstrated attack.

The attack is notable because it did not require native code execution, a V8 software exploit, or a conventional sandbox escape. Instead, it took advantage of the way co-located Workers can share an operating-system process.

How the remote Spectre attack leaked a JWT

The Cloudflare Workers platform uses V8 isolates to run code from many tenants inside the same OS process. Each Worker gets its own JavaScript heap, which allows Cloudflare to keep startup times low while avoiding the overhead of putting every tenant into a separate process. Cloudflare acknowledged that an arbitrary read inside a shared Worker process can still create a path for cross-tenant leakage.

Spectre abuses speculative execution in modern CPUs. Although the processor discards the result of an incorrect speculative operation, traces can remain in the cache. An attacker can measure those traces to infer data that should otherwise be inaccessible.

Cloudflare had already restricted high-resolution local timers, shared memory, and multithreading inside Workers. The researchers got around that obstacle by using WebSocket communications as a remote timing source.

GIGAZINE reported that the attack also used a Pseudo Least Recently Used technique to amplify tiny cache-timing differences until they could be distinguished over a noisy network connection. Durable Objects helped keep a Worker isolate alive for five to more than 20 hours while measurements were collected.

The researchers eventually recovered the deliberately planted JWT bit by bit at up to 12 bits per second with 99.16% accuracy. The Hacker News reported that the rate was about 360 times faster than a 2021 demonstration that managed roughly 120 bits per hour.

Advertisement

Why Cloudflare’s Spectre detector missed it

Cloudflare’s Dynamic Process Isolation system, known as DyPrIs, watches hardware performance counters and moves scripts that resemble Spectre attacks into separate processes.

Two characteristics of the new attack slipped past that defense.

First, DyPrIs previously waited until an invocation finished before isolating it. WebSocket keep-alive messages allowed a Durable Object invocation to continue for hours, giving the researchers time to complete the leak before isolation occurred.

Second, heavy WebSocket traffic increased iTLB activity. That lowered the normalized branch-misprediction signal used by DyPrIs below its detection threshold, making the attack resemble a normal I/O-heavy Worker.

Cloudflare adds more isolation around Workers

Cloudflare described three overlapping defenses: improving DyPrIs, integrating the V8 Sandbox, and using hardware-assisted in-process isolation.

The V8 Sandbox reduces exposure to raw 64-bit pointers, making the specific speculative gadget used in the research harder to reuse. Cloudflare cautioned that the sandbox is not a complete Spectre mitigation because other gadgets or attack variants could still be possible.

Cloudflare also uses Memory Protection Keys to put Worker heaps behind hardware-enforced memory boundaries. Access to memory protected by the wrong key is denied by the CPU, blocking the straightforward cross-isolate read demonstrated by the researchers. MPK reduces the available leakage surface, though Cloudflare said it does not eliminate Spectre risk entirely.

DyPrIs now treats long-running and I/O-heavy workloads as security cases, and Cloudflare is investigating whether repeated timer-like network activity can also help identify side-channel attacks.

Advertisement

For security teams evaluating serverless services, the research is a reminder to look beyond whether workloads are technically sandboxed. In multi-tenant environments, process boundaries, hardware-enforced memory isolation, runtime monitoring, and side-channel defenses all play a role in keeping one tenant’s code away from another tenant’s data.

Read more: For security teams tracking newly disclosed and actively exploited flaws, Microsoft’s August Patch Tuesday also brought fixes for more than 400 vulnerabilities, including a Windows zero-day already under attack.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.