Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: containers (1 article)Clear

Cloudflare fixes Containers flaw that let one customer read another's leftover disk data

Cloudflare fixed a flaw in Cloudflare Containers that let a paying customer read data other customers' containers left behind on the same shared server. Cloudflare Sandboxes, sold for running untrusted code including AI-agent code, was affected too. Each container gets a disk built with Linux thin provisioning in 64-kilobyte blocks; when a container was deleted, its blocks returned to a shared pool set to skip wiping before reuse. A new container writing only a little into a reused block left the rest holding the previous customer's data, though the attacker could not choose whose. Accomplish reported it on September 4, and Cloudflare says no customer action is needed.

Check
No customer action is required since Cloudflare fixed it service-side, but review whether sensitive workloads ran on Cloudflare Containers or Sandboxes during the exposure window.
Affected
Workloads on Cloudflare Containers or Sandboxes could have their freed disk blocks read by a later container on the same shared host before the fix.
Fix
Rely on Cloudflare's service-side fix, and for shared-tenant platforms generally, avoid writing secrets to container disk and rotate any that may have persisted.