Executive Summary
Cloudflare Security has published an official security advisory addressing a high-severity cross-tenant vulnerability within the Cloudflare Workers KV edge storage subsystem. Tracked under CVE-2026-60192, the vulnerability carries a CVSS v3.1 base score of 8.5 (High) and impacted serverless applications running across Cloudflare's global edge network.
Cloudflare Workers allows developers to deploy serverless JavaScript and WebAssembly code directly at edge points of presence (PoPs), with Workers KV providing low-latency distributed key-value storage. Under specific conditions involving rapid worker warm-start context pooling, an edge worker executing for one account could receive access tokens granting read access to another tenant's KV namespace.
Technical Root Cause: V8 Isolate Context Recycling Race Condition
To achieve millisecond startup times without container overhead, Cloudflare executes customer worker scripts within isolated Google V8 isolates running inside a multi-tenant process on edge servers. To optimize memory consumption, worker isolates are recycled through an internal worker pool once execution terminates.
Security researchers discovered that during high-throughput edge concurrency, a race condition occurred between the isolate memory cleanup routine and the injection of KV namespace credentials. In rare instances, when an isolate was rapidly assigned to a new incoming request from a different tenant, the internal binding table retained ephemeral authentication tokens belonging to the previously executed worker.
// Conceptual representation of cross-tenant token binding race condition
export default {
async fetch(request, env, ctx) {
// Under vulnerable worker pool recycling:
// env.MY_KV_NAMESPACE occasionally pointed to an adjacent tenant's storage namespace
const leakedData = await env.MY_KV_NAMESPACE.get("session_auth_keys");
return new Response(leakedData);
}
};
Cloud Blast Radius & Security Impact
Workers KV is widely utilized to store session tokens, feature flags, user authorization profiles, and cryptographic routing keys. The potential exposure of cross-tenant KV namespaces enabled:
- Unauthorized reading of session tokens and encrypted application state across co-located cloud customers.
- Exposure of internal API endpoints and private webhook signing secrets stored in edge configuration namespaces.
- Potential integrity risks if an adversary possessed write permissions to shared configuration datasets.
Remediation & Global Hotfix Deployment
Cloudflare addressed the flaw entirely within its managed edge infrastructure without requiring customer code updates or service downtime:
- Isolate Memory Zeroization: Deployed global updates to the edge execution engine enforcing complete memory zeroization and independent isolate lifecycle termination between distinct account IDs.
- Cryptographic Binding Tokens: Implemented cryptographic, single-use binding tokens for all Workers KV API calls, ensuring that an isolate cannot invoke a namespace without matching the exact account ownership hash.
- Token Revocation: Conducted comprehensive telemetry audits and invalidated all ephemeral service credentials associated with the affected isolate recycling window.



