Cloudflare fixes container tenant breach exposing customer data

Cloudflare fixed a vulnerability in containers and sandboxes that allowed customers with a Workers Paid account to retrieve residual data from other customers’ containers on the same physical host.
Cloudflare Containers is a service available as part of the Workers Paid plan that allows developers to run containerized applications on Cloudflare infrastructure, alongside Cloudflare Workers.
Developers and businesses that build applications on Cloudflare typically use it, including those running backend services, processing tasks, and code execution environments.
The flaw was reported via HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish.
Exploiting this would allow an attacker to read other clients’ files, including directory listings, SQLite databases, Chromium profiles, .env files, and credentials files.
According to Cloudflare’s disclosure, the issue involved a shared storage pool configured to skip resetting reused 64KB blocks.
“When the thin volume supporting a container’s root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains.
By writing just 4 KB to an unused region of a new container’s disk, researchers could cause a reused 64 KB physical block to be allocated. Without the reset operation, writing only 4 KB would overwrite the block, leaving the remaining 60 KB that could contain data from a previous client in a readable state.
They found residual materials on 18 of 24 container locations and 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases.
“The vulnerability would have potentially allowed a customer with a Workers Paid account to retrieve residual data from storage blocks previously used by other customers’ containers on the same underlying host,” Cloudflare explains.
“A successful exploit would have breached the boundary of tenant isolation and could have leaked file system metadata, directory structures, database pages, and application data. »
An attacker would have no control over the victim or host, nor would they be able to read an actively connected disk.
Risk assessment and actual exposure
Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not the actual contents of the disk, so no actual customer data was exposed in this evaluation.
The researchers also demonstrated no way to modify another customer’s data or disrupt their workloads on the Cloudflare service.
Cloudflare has removed the setting that caused blocks to be skipped, existing container disks removed, and cached snapshots cleared that may contain old mappings, completing all mitigation actions by September 19, 2026.
After reviewing logs, telemetry and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish.
Cloudflare has automatically patched its infrastructure and customers do not need to take any action to address the risk.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL and Atlassian for a two-hour digital summit on what attacks change at AI speed, what defenders should stop doing and how to validate, decide, remediate and revalidate at machine speed.
Save your place
Gn tech