Cloudflare Fixes Critical Vulnerability Exposing Customer Data in Containers
In a serious security lapse, Cloudflare has fixed a vulnerability that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host. The flaw, discovered by a security researcher at Accomplish, threatened the confidentiality and integrity of sensitive customer information stored in Cloudflare’s infrastructure.
Cloudflare Containers is a service available to developers running containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers. This feature allows companies to run backend services, processing jobs, and code execution environments, making it a crucial component for many businesses relying on Cloudflare’s services. The vulnerability affected customers using the Workers Paid plan, which provides additional features and capabilities.
The issue was caused by a shared storage pool that failed to zero out reused 64 KiB blocks when containers were deleted. This oversight allowed attackers to recover residual data from previous customer containers stored on the same host. By exploiting this flaw, an attacker could potentially read sensitive files, including directory listings, SQLite databases, Chromium profiles, and credential files, belonging to other customers.
According to Cloudflare’s investigation, the researchers successfully demonstrated the vulnerability by writing only 4 KiB to an unused region of a new container’s disk. This small write operation would overwrite the block containing the residual data from previous customer containers, leaving it readable for the attacker. The researchers found evidence of residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested.
While Cloudflare emphasizes that no real customer data was exposed during this evaluation, the potential consequences are severe. An attacker could potentially cross the tenant-isolation boundary, disclosing sensitive information about other customers’ file systems, directory structures, database pages, and application data.
Fortunately, Cloudflare has taken swift action to mitigate the issue. The company removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings. These mitigation actions were completed by September 19, 2026, with no evidence of customer data exposure found through logs, telemetry, or historical data analysis.
As a precautionary measure, Cloudflare applied the fixes to its infrastructure automatically, requiring customers to take no action to address the risk. This incident serves as a reminder for organizations to regularly review and update their security protocols to prevent similar vulnerabilities in the future.
For users of Cloudflare’s services, it is essential to be aware of this critical vulnerability and ensure that their applications are running on the latest version of the service with all security patches applied. Additionally, businesses should consider implementing additional security measures to protect against potential data breaches, such as encrypting sensitive information and regularly backing up critical data.
In conclusion, Cloudflare’s swift action in addressing this critical vulnerability highlights the importance of proactive security measures in preventing data exposure. As the cybersecurity landscape continues to evolve, it is crucial for organizations to stay vigilant and prioritize the confidentiality, integrity, and availability of their sensitive information.
Source: Bleeping Computer — 2026-09-27