Cloudflare fixes cross-tenant data exposure in Containers: deleted disks handed to next tenant unwiped

ziv_ravid · x · 2026-09-24

Accomplish's security team found a cross-tenant data exposure in Cloudflare Containers: when a container was deleted, its disk space was handed to the next container without being wiped, so a new container could sometimes read residual data — including full databases — left by the previous one.

Cloudflare received the responsible disclosure on September 4, 2026, has fixed the issue fleet-wide with no customer-side changes, and found no evidence of malicious exploitation in its disk-I/O telemetry. The bug also affected Cloudflare Sandboxes. Attacks couldn't target specific customers and residual data wasn't guaranteed present.

Related event: Cloudflare Containers flaw exposed residual tenant data(3 posts)→

Original post →

More from Infra

Infra channel →