Blog.Cloudflare Cloudflare Workers Adds Post-Quantum Cryptography Support
Article Content
- •Cloudflare Workers now supports post-quantum algorithms ML-KEM and ML-DSA.
- •Developers can experiment with these algorithms using the Web Crypto API.
- •The update is part of a broader effort to modernize web cryptography.
On October 1, 2026, Cloudflare announced support for modern cryptographic algorithms in its Workers platform, including post-quantum-resistant algorithms like ML-KEM and ML-DSA. This update allows developers to experiment with these algorithms in the Web Crypto API, facilitating a transition to post-quantum security. The new features include functions for key encapsulation and decapsulation, as well as signature generation and verification. While this support is currently behind a compatibility flag, it provides essential building blocks for developers to prepare their applications for the post-quantum era. The move comes as the cybersecurity community anticipates the need for stronger cryptographic protections against potential quantum computing threats. The specification for these algorithms is part of an ongoing effort to modernize cryptography on the web, with additional algorithms also proposed. This update does not represent a full migration path but offers tools for validation and integration.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Common questions
What algorithms are now supported in Cloudflare Workers?
How can developers use these new algorithms?
Is this a complete migration path to post-quantum cryptography?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…