Tech News
← Home  ·  All topics

Hackerone

2 GoKawiil briefs on this topic

Cloudflare patches storage flaw that let Containers users read other tenants' data

Cloudflare fixed a vulnerability in its Containers and Sandboxes service that let Workers Paid customers recover leftover data from other customers' containers on the same physical host. The flaw stemmed from a shared storage pool that reused 64 KiB disk blocks without zeroing them, leaving up to 60 KiB of previous customer data readable when a new customer wrote only 4 KiB to that space. Security researcher Oren Yomtov of Accomplish reported the issue via HackerOne on September 4, and testing found recoverable data—including SQLite databases, .env files, and credential files—on 18 of 24 container placements checked.

GitLab patches maximum-severity path traversal bug in commits API

GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.