Cloudflare fixes Containers cross-tenant flaw exposing customer data
Key Points:
- Cloudflare patched a vulnerability in its Containers and Sandboxes service that allowed Workers Paid customers to access residual data from other customers' containers on the same physical host.
- The flaw, reported by security researcher Oren Yomtov, stemmed from a shared storage pool that skipped zeroing out reused 64 KiB blocks, enabling attackers to read leftover data such as directory listings, databases, and credential files.
- Researchers found residual data on most tested containers and nodes, indicating the vulnerability could cross tenant isolation boundaries and expose sensitive filesystem and application data without allowing data modification or active disk access.
- Cloudflare mitigated the issue by removing the problematic setting, retiring container disks, and clearing cached snapshots by September 19, 2026, with no evidence of actual data exposure found after thorough investigation.
- The fix was applied automatically to Cloudflare’s infrastructure, requiring no customer action to eliminate the risk.