blog.cloudflare.com 24 Sept 2026, 15:00 UTC

Cloudflare Containers Flaw Exposed Data Between Customers

Cloudflare Containers Flaw Exposed Data Between Customers
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has disclosed and remediated a cross-tenant data exposure vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes, which is built on Containers. Security researcher Oren Yomtov of Accomplish reported the issue through Cloudflare’s bug bounty programme on 4 September 2026. A customer with a Workers Paid account could potentially recover residual 64 KiB storage blocks previously used by another customer’s Container on the same host.

The issue resulted from Linux device mapper thin provisioning being configured with `skip_block_zeroing`, allowing a small 4 KiB write to leave the remaining 60 KiB of a reused block unchanged. The technique could not target a specific customer, workload, host or data, and residual information was not guaranteed to be present.

In testing across six production placements, researchers identified 2,700 foreign directory inodes and observed residual material on 18 of 24 placements and 20 of 22 underlying nodes across four continents. Recovered material included directory structures, database pages and structurally complete SQLite databases. Cloudflare said the researchers supplied no third-party identifiers or recovered content and securely deleted data under their control.

The company found no evidence of malicious exploitation after reviewing historical disk-I/O telemetry; activity matching the technique was attributed to authorised testing by the researchers and Cloudflare engineers. Cloudflare removed `skip_block_zeroing`, then retired running Container disks, drained hosts, restarted virtual machines and cleared pre-mitigation cached image snapshots. Cleanup was completed across the fleet by 19 September 2026, and customers do not need to make configuration changes.

View full article

Article by CyberSIXT