Cloudflare fixes cross-tenant data exposure in Containers: deleted disks handed to next tenant unwiped
ziv_ravid · x · 2026-09-24
Accomplish's security team found a cross-tenant data exposure in Cloudflare Containers: when a container was deleted, its disk space was handed to the next container without being wiped, so a new container could sometimes read residual data — including full databases — left by the previous one.
Cloudflare received the responsible disclosure on September 4, 2026, has fixed the issue fleet-wide with no customer-side changes, and found no evidence of malicious exploitation in its disk-I/O telemetry. The bug also affected Cloudflare Sandboxes. Attacks couldn't target specific customers and residual data wasn't guaranteed present.
Related event: Cloudflare Containers flaw exposed residual tenant data(3 posts)→
More from Infra
- Perplexity Launches Fast Search API: 95% of Results in Under 230ms on Rust-Based Photon — perplexity_ai · 2026-09-25
- 100B Model Trained Across 5 Data Centers on Plain Internet Links at 30.8% MFU — markjeffrey · 2026-09-25
- AMD gaining 10 points of GPU share would be 'transformational', analyst argues — Beth_Kindig · 2026-09-25
- Google sees orbital AI data centers reaching cost parity with terrestrial ones by mid-2030s — McDonaghMatthew · 2026-09-25
- Goldman Sachs hikes AI power forecasts: 2030 data center capacity raised to 217GW — McDonaghMatthew · 2026-09-25
- Puro-2B: an open recipe trains a Qwen2-1.5B-beating LLM on RTX 5090s for just $4.4K — IgorCarron · 2026-09-25