Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Cloudflare fixed a Containers flaw that exposed other customers' leftover disk data.
Cloudflare and researchers said a flaw in Cloudflare Containers, which also underlies Cloudflare Sandboxes, let a customer read data previous containers left on shared disks. Thin-provisioned 64 KB blocks were returned to a cross-account pool without wiping, so a 4 KB write still exposed the rest of a prior tenant's block. Production tests recovered leftovers on 18 of 24 attempts, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files. Oren Yomtov of Accomplish reported it on September 4; Cloudflare restored wiping, cleared existing disks by September 19, and said retained logs showed only authorized testing.