Cloudflare Containers Flaw Exposed Cross-Tenant Data to Paid Workers Accounts
A critical vulnerability in **Cloudflare's Containers** and **Sandboxes** services, available on its **Workers Paid** plan, allowed customers to potentially recover residual data from other tenants on the same physical host. The flaw, reported by security researcher **Oren Yomtov**, stemmed from an issue with shared storage pool block zeroing, potentially exposing sensitive information like directory listings and database files.

**Cloudflare** has addressed a significant cross-tenant vulnerability within its **Containers** and **Sandboxes** offerings. This flaw could have enabled customers with a **Workers Paid** account to retrieve residual data from other customers' containers sharing the same physical host.
**Cloudflare Containers** is a service designed for developers on the **Workers Paid** plan, allowing them to run containerized applications alongside **Cloudflare Workers**. It's commonly used for backend services, job processing, and code execution environments.
### The Discovery
The vulnerability was responsibly disclosed via **HackerOne** on September 4 by **Oren Yomtov**, a security researcher at **Accomplish**. Exploiting this flaw could have granted an attacker access to other customers' files, including directory listings, **SQLite** databases, **Chromium** profiles, `.env` files, and credential files.
### Technical Details of the Flaw
According to **Cloudflare's** disclosure, the root cause lay in a shared storage pool configured to skip zeroing reused 64 KiB blocks. When a container's root disk was deleted, its physical blocks were returned to a pool serving multiple customer accounts.
Researchers discovered that by writing a mere 4 KiB to an unused region of a new container's disk, a reused 64 KiB physical block would be allocated. Without proper zeroing, only the 4 KiB write would overwrite the block, leaving the remaining 60 KiB readable. This residual data could contain information from a previous customer.
Tests revealed residual material on 18 out of 24 container placements and across 20 out of 22 underlying nodes. This included directory structures, database pages, and complete **SQLite** databases.
**Cloudflare** stated, "The vulnerability would potentially have allowed for a customer with a **Workers Paid** account to recover residual data from storage blocks previously used by other customersβ Containers on the same underlying host. A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data."
It's important to note that an attacker would not have gained control over the victim or host, nor would they have been able to read an actively attached disk.
### Risk Evaluation and Mitigation
**Cloudflare** confirmed that the researchers' activities were limited to scripts performing checks and returning aggregate counts, not actual disk contents. Therefore, no real customer data was exposed during this evaluation. The researchers also did not demonstrate any capability to alter other customers' data or disrupt their workloads.
To address the issue, **Cloudflare** promptly removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that might have contained old mappings. All mitigation actions were completed by September 19, 2026.
Following a thorough examination of logs, telemetry, and historical data, the company found no evidence of customer data exposure via the method described by **Accomplish**. The fixes were applied automatically to **Cloudflare's** infrastructure, requiring no action from customers.
