Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare patched a vulnerability in Containers and Sandboxes that let Workers Paid customers recover residual data from other customers' containers on the same host. The issue stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks. A researcher reported it via HackerOne on September 4, and all mitigations were completed by September 19, 2026.
- Flaw allowed reading other customers' files, SQLite databases and .env files
- Residual data found on 18 of 24 container placements and 20 of 22 nodes
- Root cause was skipped zeroing of reused 64 KiB blocks
- Cloudflare removed the setting, retired old disks and cleared cached snapshots
Read next
Security