Cloudflare says it fully remediated a cross-tenant data exposure in Containers and Sandboxes after Accomplish researcher Oren Yomtov reported it on September 4, with no evidence of customer compromise. The issue affected Cloudflare’s multi-tenant hosting for Workers Paid customers.
The flaw was in the storage layer: when a container’s thin-provisioned disk blocks were reused, some blocks were not zeroed first, so a new workload could recover leftover disk contents from a previous one on the same host. Customers could not pick a host or target a specific tenant, so the exposure was opportunistic data leakage, not a chosen intrusion.
For readers, the important map is that the blast radius sat between co-located tenants on shared infrastructure. Cloudflare says the fleet-wide fix and cleanup are already done, so the remaining question is what any recovered scraps may have contained before remediation, not whether the platform is still exposed.
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads.