
Cloudflare patches cross-tenant flaw that exposed residual disk data to paying customers
Cloudflare has patched a vulnerability in its Containers and Sandboxes services that allowed customers with a Workers Paid plan to read residual data from other customers' containers on the same physical host. The flaw, reported by security researcher Oren Yomtov of Accomplish on September 4, 2026, stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks. While the researchers found leftover data on 18 of 24 container placements, Cloudflare confirmed no actual customer data was exposed and that no malicious exploitation occurred. The company completed mitigation by September 19, 2026, requiring no action from users.




