Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare fixed a Containers flaw that let Workers Paid customers read residual data from other tenants on the same host.
Cloudflare fixed a Containers and Sandboxes flaw that could let a Workers Paid customer recover residual data from other customers' containers on the same physical host. A shared storage pool skipped zeroing of reused 64 KiB blocks, so a 4 KiB write could leave 60 KiB of a previous tenant's files readable, including directory listings, SQLite databases, .env files, and credentials. Researcher Oren Yomtov of Accomplish reported it via HackerOne on September 4, 2026; tests found residual material on 18 of 24 placements. Cloudflare says researchers returned only aggregate counts, found no evidence of real exposure, removed the skip-zeroing setting, and finished mitigation by September 19. Customers need take no action.
- Shared storage skipped zeroing of reused 64 KiB blocks after container disk deletion.
- A 4 KiB write could leave 60 KiB of a prior tenant's data readable.
- Residual data appeared on 18 of 24 placements and 20 of 22 nodes tested.
- Cloudflare found no evidence of real customer data exposure and required no customer action.
- Fixes, disk retirement, and snapshot clearing were completed by September 19, 2026.
Full article503 words · extracted from bleepingcomputer.com · click to collapse

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host.
Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers.
Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments.
The flaw was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish.
Exploiting it would let an attacker read other customers' files, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files.
According to Cloudflare’s disclosure, the issue was in a shared storage pool configured to skip zeroing reused 64 KiB blocks.
“When the thin volume backing a container's root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains.
By writing only 4 KiB to an unused region of a new container’s disk, the researchers could cause a reused 64 KiB physical block to be allocated. Without the zeroing operation, only the 4 KiB write would overwrite the block, leaving in a readable state the remaining 60 KiB that may contain data from a previous customer.
They found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases.
“The vulnerability would potentially have allowed for a customer with a Workers Paid account to recover residual data from storage blocks previously used by other customers’ Containers on the same underlying host,” Cloudflare says.
“A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data.”
An attacker would not have control over the victim or host, nor would they be able to read an actively attached disk.
Risk evaluation and real exposure
Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed in this evaluation.
The researchers also did not demonstrate any way to change another customer’s data or disrupt their workloads on Cloudflare’s service.
Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026.
After examining logs, telemetry, and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish.
Cloudflare applied the fixes to its infrastructure automatically, and customers need to take no action to address the risk.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.