Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    September 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Cloudflare fixes Containers cross-tenant flaw exposing customer data
    News

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    adminBy adminSeptember 27, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host.

    Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers.

    Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments.

    The flaw was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish.

    Exploiting it would let an attacker read other customers’ files, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files.

    According to Cloudflare’s disclosure, the issue was in a shared storage pool configured to skip zeroing reused 64 KiB blocks.

    “When the thin volume backing a container’s root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains.

    By writing only 4 KiB to an unused region of a new container’s disk, the researchers could cause a reused 64 KiB physical block to be allocated. Without the zeroing operation, only the 4 KiB write would overwrite the block, leaving in a readable state the remaining 60 KiB that may contain data from a previous customer.

    They found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases.

    “The vulnerability would potentially have allowed for a customer with a Workers Paid account to recover residual data from storage blocks previously used by other customers’ Containers on the same underlying host,” Cloudflare says.

    “A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data.”

    An attacker would not have control over the victim or host, nor would they be able to read an actively attached disk.

    Risk evaluation and real exposure

    Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed in this evaluation.

    The researchers also did not demonstrate any way to change another customer’s data or disrupt their workloads on Cloudflare’s service.

    Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026.

    After examining logs, telemetry, and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish.

    Cloudflare applied the fixes to its infrastructure automatically, and customers need to take no action to address the risk.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
    admin
    • Website

    Related Posts

    News

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026
    News

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    September 27, 2026
    News

    OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

    September 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202650 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202650 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Our Picks

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.