Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloads
Cloudflare patched a Containers disk-reuse flaw that could expose residual data from other customers' workloads.
Cloudflare remediated a cross-tenant data-exposure flaw in Cloudflare Containers, also affecting Sandboxes and Browser Rendering, reported on September 4, 2026, by Oren Yomtov of Accomplish. Writable disks used Linux dm-thin with skip_block_zeroing, so a newly assigned 64 KB block could retain up to 60 KB of a previous tenant's data, including filesystem metadata, SQLite pages, or .env contents. The proof of concept could not target a specific customer or live disk. Cloudflare removed the unsafe option, retired old disks, and said telemetry showed no malicious exploitation.