Cloudflare patches storage flaw that let Containers users read other tenants' data
Cloudflare fixed a vulnerability in its Containers and Sandboxes service that let Workers Paid customers recover leftover data from other customers' containers on the same physical host. The flaw stemmed from a shared storage pool that reused 64 KiB disk blocks without zeroing them, leaving up to 60 KiB of previous customer data readable when a new customer wrote only 4 KiB to that space. Security researcher Oren Yomtov of Accomplish reported the issue via HackerOne on September 4, and testing found recoverable data—including SQLite databases, .env files, and credential files—on 18 of 24 container placements checked.