Skip to content
Tech News
← Back to articles

Cloudflare patches storage flaw that let Containers users read other tenants' data

read original more articles
GoKawiil Brief

Cloudflare fixed a vulnerability in its Containers and Sandboxes service that let Workers Paid customers recover leftover data from other customers' containers on the same physical host. The flaw stemmed from a shared storage pool that reused 64 KiB disk blocks without zeroing them, leaving up to 60 KiB of previous customer data readable when a new customer wrote only 4 KiB to that space. Security researcher Oren Yomtov of Accomplish reported the issue via HackerOne on September 4, and testing found recoverable data—including SQLite databases, .env files, and credential files—on 18 of 24 container placements checked.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The bug crossed a core promise of multi-tenant cloud platforms—that one customer's workload cannot see another's data—so its scope and duration could raise questions about how thoroughly Cloudflare audits shared storage across its container infrastructure. Because exploitation only required a Workers Paid account, the pool of potential attackers was broad, though there is no indication in Cloudflare's disclosure that the flaw was exploited maliciously before the fix.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-27

Published there as: “Cloudflare fixes Containers cross-tenant flaw exposing customer data”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.