logo

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

ID: 4455e923-bd99-5846-8a92-7e941e5cb68c

STIX ID: report--4455e923-bd99-5846-8a92-7e941e5cb68c

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-08-06

Date Updated: 2026-08-07

Author: matthewsu

...
...

Check Point Research found five memory-corruption vulnerabilities in Cloudflare's workerd runtime used by Cloudflare Workers and Code Mode. Two critical issues enabled a cross-tenant out-of-bounds read (allowing secrets to be leaked from other tenants via the tcmalloc heap) and a zlib use-after-free that can be turned into a sandbox escape to run native code on the host; additional issues include an HTMLRewriter UAF and a KV SQL-bypass deserialization vector. Cloudflare fixed managed Workers in production and advised self-hosted workerd users to upgrade to v1.20260619.1; PoC code was disclosed as part of a Black Hat 2026 presentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.