Cloudflare has addressed a cross-tenant vulnerability in its Containers and Sandboxes services, which could have let malicious actors read residual data from other customers' containers. The flaw, reported via HackerOne on September 4 by security researcher Oren Yomtov at Accomplish, affected Cloudflare Containers—a service available on the Workers Paid plan that enables developers to run containerized applications on Cloudflare's infrastructure.
The issue stemmed from a shared storage pool that was configured to skip zeroing reused 64 KiB blocks. When a container's root disk was deleted, its physical blocks were returned to a pool serving multiple customer accounts. By writing only 4 KiB to an unused region of a new container's disk, an attacker could trigger the allocation of a reused 64 KiB block. Without zeroing, only the 4 KiB write would overwrite the block, leaving the remaining 60 KiB readable and potentially containing data from previous users.
Researchers found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files. Cloudflare noted that a successful exploit would cross the tenant-isolation boundary, potentially disclosing filesystem metadata, directory structures, database pages, and application data. However, the attacker would not have control over the victim or host, nor could they read an actively attached disk.
Cloudflare stated that the researchers only used scripts performing checks and returning aggregate counts, not actual disk contents, so no real customer data was exposed during the evaluation. The researchers also did not demonstrate any ability to change or disrupt other customers' workloads.
The company removed the setting causing skipped block zeroing, retired existing container disks, and cleared cached snapshots that may have contained old mappings. All mitigation actions were completed by September 19, and Cloudflare found no evidence of customer data exposure through logs, telemetry, or historical data. The fixes were applied automatically, requiring no action from customers.