Researchers exploited Cloudflare Containers flaw to read other tenants' residual disk data

matthew_d_green · x · 2026-09-24

Accomplish AI researcher Oren Yomtov responsibly disclosed a cross-tenant data exposure vulnerability in Cloudflare Containers: on multi-tenant hosts, a customer with a Workers Paid account could recover residual disk blocks left by previous workloads, including SQLite databases, Chromium profiles, and .env files. Cloudflare Sandboxes and Browser Rendering, built on the same disk implementation, were also affected.

Key points:

Related event: Cloudflare Containers flaw exposed residual tenant data(3 posts)→

Original post →

More from Infra

Infra channel →