Cloudflare patches storage flaw that let Containers users read other tenants' data
Cloudflare fixed a vulnerability in its Containers and Sandboxes service that let Workers Paid customers recover leftover data from other customers' containers on the same physical host. The flaw stemmed from a shared storage pool that reused 64 KiB disk blocks without zeroing them, leaving up to 60 KiB of previous customer data readable when a new customer wrote only 4 KiB to that space. Security researcher Oren Yomtov of Accomplish reported the issue via HackerOne on September 4, and testing found recoverable data—including SQLite databases, .env files, and credential files—on 18 of 24 container placements checked.
GoKawiil's interpretation of the reporting above, not reported fact.
The bug crossed a core promise of multi-tenant cloud platforms—that one customer's workload cannot see another's data—so its scope and duration could raise questions about how thoroughly Cloudflare audits shared storage across its container infrastructure. Because exploitation only required a Workers Paid account, the pool of potential attackers was broad, though there is no indication in Cloudflare's disclosure that the flaw was exploited maliciously before the fix.
- Cloudflare fixed a flaw letting Workers Paid customers read residual data from other tenants' deleted containers.
- The root cause was reused 64 KiB storage blocks that weren't zeroed before reallocation.
- Testing showed recoverable sensitive data, including SQLite databases and credential files, on most sampled container placements.
Source: bleepingcomputer.com, 2026-09-27
Published there as: “Cloudflare fixes Containers cross-tenant flaw exposing customer data”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.