Vulnerabilities & Exploits

Cloudflare Fixed Cross-Tenant Storage Leakage

Cloudflare says it fully remediated a cross-tenant data exposure in Containers and Sandboxes after Accomplish researcher Oren Yomtov reported it on September 4, with no evidence of customer compromise. The issue affected Cloudflare’s multi-tenant hosting for Workers Paid customers.

The flaw was in the storage layer: when a container’s thin-provisioned disk blocks were reused, some blocks were not zeroed first, so a new workload could recover leftover disk contents from a previous one on the same host. Customers could not pick a host or target a specific tenant, so the exposure was opportunistic data leakage, not a chosen intrusion.

For readers, the important map is that the blast radius sat between co-located tenants on shared infrastructure. Cloudflare says the fleet-wide fix and cleanup are already done, so the remaining question is what any recovered scraps may have contained before remediation, not whether the platform is still exposed.

3 sources · 22h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-28

Every edition of this story: Cloudflare Fixed Cross-Tenant Storage Leakage

More from today