Cloudflare patches Containers bug that leaked data between customers

Cloudflare fixed a vulnerability in Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other customers' containers on the same physical host. The issue involved a shared storage pool that skipped zeroing reused 64 KiB blocks, potentially exposing files, SQLite databases, environment files, and credentials. A researcher reported it through HackerOne on September 4, and testing found residual data on many container placements and nodes.
Cloudflare's Containers and Sandboxes service had a cross-tenant storage flaw. A shared pool reused 64 KiB blocks without clearing them. A small 4 KiB write could allocate such a block and leave roughly 60 KiB readable, potentially revealing files, SQLite databases, environment files, or credentials.
Researcher Oren Yomtov of Accomplish reported it via HackerOne on Sept 4. Tests found leftover information on 18 of 24 placements and 20 of 22 nodes. Cloudflare removed the zeroing-skip setting, retired disks, and cleared cached snapshots by Sept 19; it found no evidence of actual customer information being exposed.
Cloudflare’s fix may reassure developers who rely on its Workers Paid platform, but the incident could still affect trust in multi-tenant cloud isolation. If similar flaws existed elsewhere, businesses and their users might face credential leaks or database exposure. The reported lack of confirmed real-world exposure and automatic remediation may limit immediate harm, yet the case could push cloud providers to audit storage reuse, data zeroing, and tenant separation more rigorously.