Cloudflare Fixes Containers Flaw That Exposed Residual Data


cloudeflare flaw fixed
Image credit: Cloudflare

Cloudflare has fixed a vulnerability in its Containers and Sandboxes services that could allow Workers Paid customers to recover residual data left behind by other customers using the same physical host.

Potentially exposed information included directory listings, SQLite databases, Chromium profiles, .env files, and credential files.

Security researcher Oren Yomtov of Accomplish reported the vulnerability through HackerOne on September 4.

Reused storage blocks were not fully cleared

The vulnerability stemmed from a shared storage pool configuration that skipped zeroing reused 64 KiB blocks after a container disk had been deleted.

Researchers found that writing only 4 KiB to a reused 64 KiB block could leave the remaining 60 KiB readable. That space could still contain data from a previous customer.

Residual material appeared on 18 of 24 container placements across 20 of 22 tested nodes.

However, attackers could not select a specific victim, access disks that were actively attached, modify another customer’s data, or disrupt workloads.

Cloudflare found no evidence of customer data exposure

The researchers used scripts that returned aggregate results instead of reading actual customer data, so their testing did not expose real customer information.

Cloudflare also reviewed logs, telemetry, and historical information and found no evidence that attackers had exploited the vulnerability to expose customer data.

Cloudflare completed mitigation by September 19

Cloudflare removed the configuration that allowed storage blocks to skip zeroing. The company also retired existing container disks and cleared cached snapshots containing older storage mappings.

Cloudflare completed the mitigation work by September 19, 2026.

The fixes were applied automatically across Cloudflare’s infrastructure, so customers do not need to take any action.

In other news, OpenAI Security Controls and OpenAI Agents and Medicare Systems raised fresh questions about how AI systems handle access restrictions.

Via BleepingComputer

More about the topics: Cybersecurity

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages