Cloudflare fixed a flaw in Containers and Sandboxes that could have let customers on a Workers Paid account recover residual data from other customers’ containers on the same physical host.
Security researcher Oren Yomtov of Accomplish reported the issue through HackerOne on September 4. The flaw involved a shared storage pool that did not zero reused 64 KiB blocks. A 4 KiB write to a new container’s disk could overwrite only part of a reused block, leaving the remaining 60 KiB readable. That data could include directory listings, SQLite databases, Chromium profiles, .env files, and credential files.
Researchers found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes they tested. Cloudflare said a successful attack could have crossed tenant isolation and exposed filesystem metadata, database pages, and application data. An attacker could not control a victim or host, read an actively attached disk, alter another customer’s data, or disrupt workloads.
The researchers used scripts that returned aggregate counts, not disk contents, and Cloudflare said no real customer data was exposed in the evaluation. After reviewing logs, telemetry, and historical data, Cloudflare found no evidence of customer data exposure through the method. The company removed the setting that skipped zeroing, retired existing container disks, and cleared cached snapshots that might contain old mappings. It completed these measures by September 19, 2026. The fixes were applied automatically; customers do not need to act.
Comments
0No comments yet. Be the first to comment.