A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company has fixed the flaw across its service and says customers need to do nothing.
Cloudflare Containers runs customers' programs inside containers on servers shared by many accounts, and Cloudflare, not the customer, picks the server. Cloudflare Sandboxes, which runs on Containers and is sold as a safe place to run untrusted code, including code written by AI agents, was affected too.
The flaw was reported on September 4 by Oren Yomtov of the security firm Accomplish, through Cloudflare's bug bounty program.
The problem was in how the shared disks were set up. Each container gets a disk built using a Linux feature called thin provisioning, which allocates storage in 64-kilobyte blocks. When a container was deleted, its blocks returned to a pool shared across customer accounts.
That pool was set to skip wiping a block before handing it to the next container, and wiping is normally the default. So when a new container wrote only a small amount into a reused block, the rest of the block still held the previous container's data.
To reach it, the researchers wrote a small four-kilobyte block into unused space and then read the whole block back at the raw disk level.
Source link







![Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](https://images.themorningpulse.fyi/uploads/2026/09/rss-mufvac1h-vu0lfo-media.jpg)