Cloudflare fixes Containers flaw that could expose other customers’ residual data

· Original article ↗

Summary

A flaw in Cloudflare Containers could let Workers Paid customers recover residual data from other customers’ containers on the same host. Cloudflare fixed the issue and found no evidence of customer data exposure.

Key points

  • The flaw affected Cloudflare Containers and Sandboxes, which run on the Workers Paid plan.
  • A shared storage pool failed to zero reused 64 KiB blocks when container disks were deleted, potentially leaving prior customers’ data readable.
  • Researchers reported finding residual data on 18 of 24 container placements and 20 of 22 underlying nodes tested.
  • Potentially accessible material included directory listings, SQLite databases, Chromium profiles, .env files, and credential files.
  • The researchers used checks that returned aggregate counts and did not access actual customer disk contents; they also found no way to alter other customers’ data or disrupt workloads.
  • Cloudflare removed the setting, retired existing container disks, and cleared cached snapshots by September 19, 2026. It found no evidence of customer data exposure, and customers need take no action.

Article Details

Event Type
Cross-tenant data exposure vulnerability fixed
Impact
A Workers Paid customer could potentially read residual files from other customers’ Containers on the same physical host, including database pages and credential files. Researchers found residual material during testing but did not access actual customer data. Cloudflare found no evidence of customer data exposure through this method.

Vendors

Products

Related Articles