Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has recently addressed a significant vulnerability in its Containers and Sandboxes service that allowed malicious actors to potentially access sensitive information from other customers’ applications running on the same physical host. This security flaw, which was discovered by a researcher at Accomplish and reported through HackerOne, could have had far-reaching consequences for Cloudflare’s customers.

The issue, which has now been fixed, involved a shared storage pool that didn’t properly zero out reused blocks of data. When a customer’s container was deleted, its physical blocks were returned to a pool used by multiple accounts, leaving behind residual data from previous users. By exploiting this vulnerability, an attacker with access to the Cloudflare Workers Paid plan could have read sensitive files and directories belonging to other customers, including directory listings, SQLite databases, Chromium profiles, and credential files.

Cloudflare’s Containers service is designed for developers who need to run containerized applications on its infrastructure alongside its Cloudflare Workers. This service typically caters to companies building backend services, processing jobs, and code execution environments. The affected vulnerability was particularly concerning because it allowed an attacker to bypass tenant isolation boundaries, potentially disclosing sensitive information about other customers’ file systems.

Thankfully, the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed during their evaluation. Moreover, they didn’t demonstrate any way to modify another customer’s data or disrupt their workloads on Cloudflare’s service. After analyzing logs, telemetry, and historical data, Cloudflare found no evidence of customer data exposure via this method.

Cloudflare has since addressed the issue by removing the setting that caused the skipped block zeroing, retiring existing container disks, and clearing cached snapshots that may contain old mappings. The company applied these fixes to its infrastructure automatically, so customers don’t need to take any action to address the risk.

While this vulnerability was significant, it’s worth noting that Cloudflare’s quick response and mitigation actions demonstrate a commitment to customer security and data protection. This incident serves as a reminder of the importance of ongoing security monitoring and the value of responsible disclosure in identifying and addressing potential vulnerabilities before they can be exploited by malicious actors.


Source: Bleeping Computer — 2026-09-27