Cloudflare fixes cross-tenant flaw: unzeroed storage blocks leaked customer container data
arpit_bhayani · x · 2026-09-28
A detailed breakdown of the Cloudflare Containers/Sandboxes cross-tenant data exposure flaw.
Root cause
- The shared storage pool was configured to skip zeroing reused 64 KiB blocks when a volume was deleted
- Containers use thin volumes that allocate physical blocks on first write, so writing just 4 KiB to an unused region triggered allocation of a reused block — leaving the other 60 KiB readable with the previous tenant's data
Impact
- Workers Paid customers could read residual files from other customers' containers: directory listings, SQLite databases, Chromium profiles, .env and credential files
- Residual data was found on 18 of 24 container placements and 20 of 22 underlying nodes tested
Disclosure
Reported Sept 4 via HackerOne by Oren Yomtov (Accomplish); Cloudflare has fixed it and published a disclosure.
Related event: Cloudflare Patches Cross-Tenant Leak from Unwiped Storage Blocks(2 posts)→
More from Infra
- AI code-sandbox provider Daytona officially moves to new domain — glcst · 2026-09-28
- YC F26's WonderSearch searches millions of documents without pre-embedding the corpus — KlausCodes · 2026-09-28
- NVIDIA consumer GPUs likely under 10% of revenue — time to fix melting connectors — qtnx_ · 2026-09-28
- Cloudflare launches cf: an agentic CLI covering its entire API as agent usage hits 48% — irvinebroque · 2026-09-28
- Memory price forecasts diverge 25+ points: Jefferies sees 40-50% Q3 surge vs TrendForce 13-18% — Beth_Kindig · 2026-09-28
- Unsloth runs Laya Decision models locally on just 4GB RAM across CPU, Mac and GPU — danielhanchen · 2026-09-28