Researchers exploited Cloudflare Containers flaw to read other tenants' residual disk data
matthew_d_green · x · 2026-09-24
Accomplish AI researcher Oren Yomtov responsibly disclosed a cross-tenant data exposure vulnerability in Cloudflare Containers: on multi-tenant hosts, a customer with a Workers Paid account could recover residual disk blocks left by previous workloads, including SQLite databases, Chromium profiles, and .env files. Cloudflare Sandboxes and Browser Rendering, built on the same disk implementation, were also affected.
Key points:
- The technique could not target specific customers, workloads, hosts, or data, and residual data was not guaranteed to be present
- Cloudflare has fully remediated the issue fleet-wide with no customer-side changes required
- Disk-I/O telemetry showed no evidence of malicious exploitation; all attributable activity came from researchers and authorized validation
- Cloudflare published a detailed technical postmortem on its official blog
Related event: Cloudflare Containers flaw exposed residual tenant data(3 posts)→
More from Infra
- yetone teases 'One more thing' LLM gateway, dev installs it on day one — vista8 · 2026-09-25
- Google's Project Suncatcher to launch prototype datacenter satellite on Falcon 9 Oct 1 — McDonaghMatthew · 2026-09-25
- Lightmatter CEO: moving lasers onto 300mm silicon wafers to unlock optical interconnect — BenBajarin · 2026-09-25
- Oracle Says Datacenter Force-Majeure Notice Doesn't Mean Project Delay — ns123abc · 2026-09-25
- 100MW+ Datacenters Wait 5-10 Years for Grid Power; Cato Says Let Firms Build Their Own — McDonaghMatthew · 2026-09-25
- Four scaling paradigms keep postponing the wall: params, CoT, recurrent depth, multi-agent — gordic_aleksa · 2026-09-25