Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    Bitcoin’s Quantum Problem: Three Ways Researchers Are Trying to Fix It

    September 27, 2026

    Glucosamine, a popular joint supplement, linked to faster Alzheimer’s progression

    September 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cloudflare fixes Containers cross-tenant flaw exposing customer data
    • Bitcoin’s Quantum Problem: Three Ways Researchers Are Trying to Fix It
    • Glucosamine, a popular joint supplement, linked to faster Alzheimer’s progression
    • True Crime Reports: The Dosa King’s Deadly Obsession | Digital Series
    • Three in four UK GPs ‘too busy to talk to their patients in depth’ | GPs
    • What’s the Best Pet DNA Test? We Tested the Most Popular Ones
    • Adjusted stablecoin volume drops in Visa data reset
    • Labour is nostalgic for two-party politics. That cosy, simple time is over – let it go | John Harris
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 27, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host.

    Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers.

    Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments.

    The flaw was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish.

    Exploiting it would let an attacker read other customers’ files, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files.

    According to Cloudflare’s disclosure, the issue was in a shared storage pool configured to skip zeroing reused 64 KiB blocks.

    “When the thin volume backing a container’s root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains.

    By writing only 4 KiB to an unused region of a new container’s disk, the researchers could cause a reused 64 KiB physical block to be allocated. Without the zeroing operation, only the 4 KiB write would overwrite the block, leaving in a readable state the remaining 60 KiB that may contain data from a previous customer.

    They found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases.

    “The vulnerability would potentially have allowed for a customer with a Workers Paid account to recover residual data from storage blocks previously used by other customers’ Containers on the same underlying host,” Cloudflare says.

    “A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data.”

    An attacker would not have control over the victim or host, nor would they be able to read an actively attached disk.

    Risk evaluation and real exposure

    Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed in this evaluation.

    The researchers also did not demonstrate any way to change another customer’s data or disrupt their workloads on Cloudflare’s service.

    Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026.

    After examining logs, telemetry, and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish.

    Cloudflare applied the fixes to its infrastructure automatically, and customers need to take no action to address the risk.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Cloudflare Containers CrossTenant customer data Exposing Fixes Flaw
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adjusted stablecoin volume drops in Visa data reset

    Some Supabase customers are publicly exposing reams of people’s data to the web

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    Suffolk and Essex NHS remove 10 staff over Noah Woods data breach

    AI Coding Agents for Enterprise: IP Indemnity, Data Residency and 500-Seat Cost Compared

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    Bitcoin’s Quantum Problem: Three Ways Researchers Are Trying to Fix It

    September 27, 2026

    Glucosamine, a popular joint supplement, linked to faster Alzheimer’s progression

    September 27, 2026

    True Crime Reports: The Dosa King’s Deadly Obsession | Digital Series

    September 27, 2026
    Latest Posts

    Inside the Secretive Deal for a $10 Billion Data Center in Rural North Carolina

    August 6, 2026

    Sugar may have been a key ingredient in human evolution

    August 6, 2026

    Hyperscale sells Bitcoin for AI business set to deliver less than 20% of 2027 revenue

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    Bitcoin’s Quantum Problem: Three Ways Researchers Are Trying to Fix It

    September 27, 2026

    Glucosamine, a popular joint supplement, linked to faster Alzheimer’s progression

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.