News Date: 2026-09-27
Cloudflare has fixed a cross-tenant storage vulnerability affecting its Containers and Sandboxes services. The flaw created a path for a customer with a Workers Paid account to recover fragments of data left behind by other customers whose workloads had previously occupied the same physical storage.
How residual data became readable
The problem involved a shared storage pool that did not properly erase reused 64 KiB blocks. When a container disk was deleted, its physical blocks returned to a pool serving workloads from multiple customer accounts. A new container could write a small amount of data to one of those blocks while leaving much of its previous content intact and readable.
Researchers encountered residual material across a significant portion of their test placements. Recoverable information included directory structures, SQLite database pages, Chromium profiles, environment files and credential-related files. The attacker could not select a particular victim, access an active disk or modify another tenant's workload, but random disclosure is still a serious failure of cloud isolation.
Cloudflare's response
Cloudflare removed the configuration that skipped storage-block zeroing, retired existing container disks and cleared cached snapshots that might preserve old mappings. The company completed mitigation by September 19 and deployed the changes automatically, so customers do not need to install an update.
Cloudflare also reviewed historical telemetry and reported finding no evidence that the technique had been used to expose customer information. The security researchers limited their testing to validation scripts and aggregate measurements rather than collecting actual customer files.
Lessons for cloud customers
- Avoid storing long-lived credentials in container filesystems.
- Use managed secret stores and short-lived workload identities.
- Remove sensitive temporary files before terminating workloads.
- Include provider isolation failures in cloud risk assessments.
In my view, the incident is a reminder that a sandbox is only as strong as every infrastructure layer underneath it. Container isolation, access controls and application security cannot compensate for storage that retains another tenant's data. Cloud providers should treat secure block erasure as a foundational control, while customers should design workloads on the assumption that temporary disks are not appropriate places for durable secrets.
