Cloudflare has fixed a vulnerability in its Containers and Sandboxes service that could have allowed customers on the Workers Paid plan to recover leftover data from other customers’ containers running on the same physical host.

Cloudflare Containers lets developers run containerized workloads alongside Cloudflare Workers, and is used for backend services, batch jobs, and code execution environments. The bug was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at Accomplish.

The root cause was a shared storage pool configured to skip zeroing reused 64 KiB blocks. When a container’s root disk volume was deleted, its physical blocks were returned to a pool shared across multiple customer accounts without being wiped. By writing just 4 KiB into an unused region of a new container’s disk, a physical 64 KiB block already containing old data could be allocated, leaving the remaining 60 KiB readable.

Scope of exposure

Testing found residual material in 18 of 24 container placements and across 20 of 22 underlying nodes examined, including directory structures, database pages, and intact SQLite databases. Exploitation could expose:

  • Directory listings and filesystem metadata
  • SQLite databases and database pages
  • Chromium browser profiles
  • .env configuration files
  • Credential files

Cloudflare confirmed that a successful exploit would have crossed the tenant-isolation boundary between customers on shared infrastructure. However, an attacker would not gain control over the victim’s workload or the host itself, and could not read an actively attached disk.

No confirmed real-world exposure

According to Cloudflare, the researchers who found the flaw only ran scripts to detect the condition and return aggregate counts, never accessing actual customer disk contents. No method to alter another customer’s data or disrupt workloads was demonstrated.

After reviewing logs, telemetry, and historical records, Cloudflare says it found no evidence the technique was ever used to expose real customer data prior to disclosure.

Remediation

Cloudflare removed the configuration setting responsible for skipping block zeroing, retired existing container disks, and cleared cached snapshots that could contain stale block mappings. All mitigation steps were completed by September 19, 2026. The fixes were applied automatically across Cloudflare’s infrastructure, and no customer action is required.