Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Cloudflare

How Cloudflare Addressed a Cross-Tenant Data Exposure Vulnerability in Containers

Cloudflare, Thursday, September 24th, 2026

Cloudflare fixed a Containers vulnerability that let a customer recover residual disk data from other tenants' past workloads.

A security researcher from Accomplish responsibly disclosed a vulnerability in Cloudflare Containers and Sandboxes through Cloudflare's bug bounty program, which Cloudflare has fully remediated with no evidence of customer data compromise.

Because Containers run on multi-tenant infrastructure using Linux device-mapper thin provisioning with a 64 KiB thin-block size, the researchers demonstrated that a Workers Paid customer could recover residual disk blocks previously used by other containers on the same host, though the technique couldn't target a specific customer or data.

Cloudflare applied a fleet-wide fix requiring no customer action and found no evidence of malicious exploitation in its telemetry.

more →  ·  More from Cloudflare →