{
  "id": 12111687,
  "title": "Cloudflare Fixes Cross-Tenant Data Exposure in Containers",
  "url": "https://urgent.news/2026/10/05/cloudflare-fixes-cross-tenant-data-exposure-in-containers",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T08:48:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/10/cloudflare-cross-tenant-exposure/"
  },
  "original_language": "en",
  "account": "Cloudflare identified a vulnerability allowing cross-tenant data exposure in its Containers platform, which powers Cloudflare Sandboxes. The issue enabled a customer on a Workers Paid account to access residual disk blocks from other customers' containers sharing the same host. Cloudflare determined no malicious exploitation had occurred. The flaw originated at the storage allocator level, not within virtual machine boundaries. Security researcher Oren Yomtov discovered the problem via Cloudflare's bug bounty program on September 4. Containers utilized a 64 KiB thin-block size and skip_block_zeroing, which prevented zeroing newly allocated blocks. This combination created a gap, allowing an attacker to write a single 4 KiB block into an unmapped region, leading to the allocation of a 64 KiB physical block shared across customer accounts. The overwritten portion left up to 60 KiB of residual data that could still contain previous container data. Upon detection, Cloudflare immediately addressed the issue by closing the vulnerability, retiring running container disks, clearing host caches, and rolling out the fix over several days.",
  "summary": "Cloudflare has disclosed a cross-tenant data exposure vulnerability in Containers and Sandboxes, caused by thin-provisioned storage pools configured to skip zeroing reused blocks. Researchers recovered directory structures, database pages and complete SQLite databases across four continents. Cloudflare remediated it and found no evidence of exploitation. By Steef-Jan Wiggers",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}