Cloudflare fixes Containers cross-tenant flaw exposing customer data Cloudflare fixed a cross-tenant vulnerability in Cloudflare Containers and Sandboxes that let Workers Paid account holders recover residual data from other customers' containers on the same physical host, according to the company's disclosure. Security researcher Oren Yomtov of Accomplish reported the flaw via HackerOne on September 4; it stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks, and testing found residual material on 18 of 24 container placements and 20 of 22 underlying nodes. Cloudflare removed the setting, retired existing container disks, and cleared cached snapshots by September 19, 2026, and said it found no evidence customer data was exposed. Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host. Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers. Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments. The flaw was reported through HackerOne on September 4 by Oren Yomtov https://www.linkedin.com/in/orenyomtov/ , a security researcher at technology company Accomplish. Exploiting it would let an attacker read other customers' files https://accomplish.ai/blog/escaping-the-cloudflare-sandbox/ , including directory listings, SQLite databases, Chromium profiles, .env files, and credential files. According to Cloudflare’s disclosure, the issue was in a shared storage pool configured to skip zeroing reused 64 KiB blocks. “When the thin volume backing a container's root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains https://blog.cloudflare.com/containers-cross-tenant-vulnerability/ . By writing only 4 KiB to an unused region of a new container’s disk, the researchers could cause a reused 64 KiB physical block to be allocated. Without the zeroing operation, only the 4 KiB write would overwrite the block, leaving in a readable state the remaining 60 KiB that may contain data from a previous customer. They found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases. “The vulnerability would potentially have allowed for a customer with a Workers Paid account to recover residual data from storage blocks previously used by other customers’ Containers on the same underlying host,” Cloudflare says. “A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data.” An attacker would not have control over the victim or host, nor would they be able to read an actively attached disk. Risk evaluation and real exposure Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed in this evaluation. The researchers also did not demonstrate any way to change another customer’s data or disrupt their workloads on Cloudflare’s service. Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026. After examining logs, telemetry, and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish. Cloudflare applied the fixes to its infrastructure automatically, and customers need to take no action to address the risk. Build your security blueprint for AI-powered attacks https://hubs.li/Q04x67m50 Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat https://hubs.li/Q04x67m50