Cloudflare patches cross-tenant flaw that exposed residual disk data to paying customers

Cloudflare has patched a vulnerability in its Containers and Sandboxes services that allowed customers with a Workers Paid plan to read residual data from other customers' containers on the same physical host. The flaw, reported by security researcher Oren Yomtov of Accomplish on September 4, 2026, stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks. While the researchers found leftover data on 18 of 24 container placements, Cloudflare confirmed no actual customer data was exposed and that no malicious exploitation occurred. The company completed mitigation by September 19, 2026, requiring no action from users.
Key points
- The vulnerability affected Cloudflare Containers and Sandboxes, allowing a paying customer to read residual data from other customers' containers on the same host.
- The flaw was caused by a shared storage pool configured to skip zeroing reused 64 KiB blocks, leaving 60 KiB of previous data readable after a new 4 KiB write.
- Security researcher Oren Yomtov of Accomplish reported the issue via HackerOne on September 4, 2026.
- Cloudflare fixed the issue by re-enabling block zeroing, retiring existing container disks, and clearing cached snapshots, completing mitigation by September 19, 2026.
- Cloudflare found no evidence of malicious exploitation or compromised customer data, and customers need not take any action.
Background
This incident follows a 2026 Spectre cross-tenant leak in Cloudflare Workers, which prompted stronger isolation measures. It also occurs amid broader concerns about shared-infrastructure isolation, as seen in the Pentagon's DMDC breach exposing unencrypted data of millions of troops. Cloudflare's stock had recently risen 29% over the past month, reaching new highs before the disclosure.
How outlets are covering it
BleepingComputer and The Hacker News emphasize the technical details of the flaw, noting that the researchers found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes. Cloudflare's blog highlights the mitigation steps, including re-enabling block zeroing and retiring existing container disks. The Globe and Mail focuses on the market impact, noting Cloudflare's stock fell 3.2% after the disclosure, though it later recovered to $348.63. The Hacker News also notes that the researchers described the flaw as their sixth escape from a code sandbox since July, while Cloudflare's post did not mention Browser Run, which the researchers said was also affected.
Why it matters
The incident highlights the risks of shared-infrastructure isolation in cloud services, where residual data from one customer's container could potentially be read by another. It underscores the importance of proper data zeroing and isolation in multi-tenant environments, and the need for robust security measures to prevent cross-tenant data exposure.
What to watch
Cloudflare has completed mitigation and found no evidence of malicious exploitation. The company will continue to monitor for any signs of the method being used by others, though it did not specify the time span of the records it reviewed. Customers need not take any action, but the incident may prompt further scrutiny of Cloudflare's isolation measures and potentially impact investor confidence.
- Cloudflare fixes Containers cross-tenant flaw exposing customer data BleepingComputer
- How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers Cloudflare Blog
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data The Hacker News
- Cloudflare (NET) Stock Trades Down, Here Is Why The Globe and Mail
- Cloudflare Containers vulnerability allowed data leakage scworld.com
Want the full story? Read the original reporting
Read on BleepingComputer