Cloudflare Containers Flaw Exposed Leftover Customer Disk Data to Other Tenants; Platform Fixed It and Found No Evidence of Abuse

Cloudflare Containers Flaw Exposed Leftover Customer Disk Data to Other Tenants; Platform Fixed It and Found No Evidence of Abuse

Cloudflare Containers Flaw Exposed Leftover Customer Disk Data to Other Tenants; Platform Fixed It and Found No Evidence of Abuse

Cloudflare has fixed a flaw in its Containers service that let a paying customer read data other customers' containers had left behind on the same server. The issue was reported on September 4 by Oren Yomtov of security firm Accomplish through Cloudflare's bug bounty program and disclosed Thursday, September 24. The exposed data came from disk space that earlier containers had used and given up — not from live workloads — and an attacker could not choose whose data they received. Cloudflare says customers need to do nothing.

The mechanics sit in how shared disks were provisioned. Each container gets a disk built with Linux thin provisioning, which allocates storage in 64-kilobyte blocks. When a container was deleted, its blocks returned to a pool shared across customer accounts — and that pool was set to skip wiping a block before handing it to the next container, although wiping is normally the default. A new container that wrote only a small amount into a reused block left the rest of that block holding the previous tenant's bytes. The researchers proved it simply: write a four-kilobyte block into unused space, read the whole 64KB block back at the raw disk level, and the 60KB never written still contained another customer's data.

In production tests they found leftover material on 18 of 24 tries, across 20 of 22 underlying machines on four continents. The recovered blocks held directory structures, database pages and structurally complete SQLite databases; the researchers' own write-up lists directory listings, SQLite databases, Chromium browser profiles, .env files and credential files — other customers' files. Their analysis scripts output only counts and format checks, no third-party names or recovered content went to Cloudflare, and the material was kept private and securely deleted. There was no evidence the flaw could modify another customer's live data or take a workload offline.

Cloudflare fixed it in two steps: wiping was restored for newly allocated blocks (the researchers confirmed on September 14 their proof of concept no longer worked), then every running container disk was retired and server image-layer caches cleared, with servers drained and restarted during quiet hours — finished September 19, disclosed five days later. A hunt using detection signatures built from the PoC found only the researchers' and Cloudflare's own authorized testing; how long the unsafe setting existed is not stated. Cloudflare Sandboxes — sold as a safe place to run untrusted code, including AI-generated code — was affected, and the researchers separately say the same disk setup affected Browser Run, which Cloudflare's post did not mention. It is the team's sixth sandbox escape published since July, after findings in Claude Cowork, Claude Code, Cursor's CLI, Docker and OpenAI's Codex.

What Should You Do?

  1. Cloudflare customers: no action is required — the flaw is fixed platform-wide, and Cloudflare's log hunt found no evidence anyone else used the method.
  2. Users of multi-tenant platforms: add data-at-rest hygiene to vendor reviews — ask how storage is zeroed between tenants and how image layer caches are cleared.
  3. If you run shared infrastructure: verify that block wiping or zeroing is actually on before re-allocation, and test it — the flaw existed because a default got flipped off.
  4. Treat sandboxes as semi-permeable. Six published escapes from one team since July is a pattern, not a fluke; run untrusted code on the assumption it can reach its neighbors' leftovers.

The WAF Angle

This is the bug class no WAF will ever see: cross-tenant data remanence lives below the HTTP request, in the storage layer of shared infrastructure. It also continues 2026's defining pattern, where the interesting breaks happen at the boundary between untrusted code and someone else's data — the same researchers broke out of OpenAI's Codex sandbox weeks earlier, and Cloudflare's edge has seen cross-tenant leakage research before with the Workers Spectre findings. For defenders the moves are architectural: encrypt everything that lands on shared storage, treat AI-agent sandboxes as hostile-neighbor environments, and put data remanence questions into vendor risk reviews. Cloudflare handled this well — fast fix, transparent disclosure, a real abuse hunt — but the honest read is that the tenant boundary held only until somebody checked the disk.

Sources