Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Wants to Ban U.S. Diesel Exports to Bring Down Prices. It Won’t Help.

    September 25, 2026

    Argentina’s poverty rate climbs to nearly one in three under Milei

    September 25, 2026

    2027 : LE BAROMÈTRE DU REJET – POLITICO

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Wants to Ban U.S. Diesel Exports to Bring Down Prices. It Won’t Help.
    • Argentina’s poverty rate climbs to nearly one in three under Milei
    • 2027 : LE BAROMÈTRE DU REJET – POLITICO
    • New policies, election speculation: What to expect from Burnham’s first Labour conference as PM
    • Two-year waiting times highlight NHS struggle with rise in ADHD and autism awareness | Autism
    • Lightspeed targets $250M for new India fund, focusing on early-stage AI
    • Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data
    • Ondo unlocks BlackRock portfolio strategies, but only non-US traders benefit
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 25, 2026Cloud Security / Vulnerability

    A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.

    The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company has fixed the flaw across its service and says customers need to do nothing.

    Cloudflare Containers runs customers’ programs inside containers on servers shared by many accounts, and Cloudflare, not the customer, picks the server. Cloudflare Sandboxes, which runs on Containers and is sold as a safe place to run untrusted code, including code written by AI agents, was affected too.

    The flaw was reported on September 4 by Oren Yomtov of the security firm Accomplish, through Cloudflare’s bug bounty program.

    The problem was in how the shared disks were set up. Each container gets a disk built using a Linux feature called thin provisioning, which allocates storage in 64-kilobyte blocks. When a container was deleted, its blocks returned to a pool shared across customer accounts.

    Cybersecurity

    That pool was set to skip wiping a block before handing it to the next container, and wiping is normally the default. So when a new container wrote only a small amount into a reused block, the rest of the block still held the previous container’s data.

    To reach it, the researchers wrote a small four-kilobyte block into unused space and then read the whole block back at the raw disk level. The 60 kilobytes they had not written still held bytes from a previous container.

    Across production tests, they reported finding leftover material on 18 of 24 tries, each on a server Cloudflare chose, and on 20 of 22 underlying machines across four continents.

    The recovered blocks held directory structures, database pages, and structurally complete SQLite databases, Cloudflare said; the researchers’ own write-up lists directory listings, SQLite databases, Chromium browser profiles, .env files, and credential files, and describes them as other customers’ files.

    The researchers reported that their analysis scripts output only counts and format checks, not file contents, and that the material they sent Cloudflare contained no third-party names, identifiers, credentials, or recovered content.

    They also confirmed the recovered data was kept private and securely deleted after they submitted it, Cloudflare said. The researchers did not show that the flaw could change another customer’s live data or take a workload offline.

    Cloudflare fixed the flaw in two steps. It first turned wiping back on for newly handed-out blocks, which stopped the reported method; the researchers confirmed on September 14 that their proof of concept no longer worked.

    Cybersecurity

    But that change did not clean blocks already mapped into running container disks or into each server’s cache of prepared image layers, which a new container could inherit and read. So Cloudflare also retired every running container disk and cleared those caches, draining and restarting servers during quiet hours. It finished that cleanup on September 19, and disclosed the flaw five days later.

    Cloudflare said it looked for signs that anyone else had used the method. It built detection signatures from the researchers’ proof of concept and its own copy of the attack and ran them against the disk-activity records it had kept. It found only the researchers’ and its own engineers’ authorized testing, and said it saw no evidence that this specific method was used by anyone else.

    That finding covers the records Cloudflare retained, though it did not state the time span or when the unsafe setting was first put in place, so how long the exposure lasted is not clear from its account.

    The researchers, who separately say the same disk setup affected Cloudflare’s Browser Run product, described the flaw as their sixth escape from a code sandbox published since July, after findings in Anthropic’s Claude Cowork and Claude Code, Cursor’s command-line tool, Docker, and OpenAI’s Codex. Cloudflare’s post named Containers and Sandboxes as affected and did not mention Browser Run.

    Cloudflare container customers data Disk Fixes Flaw Leftover Read
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    New Carbonato malware uses AI agents to hijack exposed Docker hosts

    WordPress patches a critical severity security vulnerability

    Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    Begin at the End: How to Enable Agentic Remediation

    Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Wants to Ban U.S. Diesel Exports to Bring Down Prices. It Won’t Help.

    September 25, 2026

    Argentina’s poverty rate climbs to nearly one in three under Milei

    September 25, 2026

    2027 : LE BAROMÈTRE DU REJET – POLITICO

    September 25, 2026

    New policies, election speculation: What to expect from Burnham’s first Labour conference as PM

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Wants to Ban U.S. Diesel Exports to Bring Down Prices. It Won’t Help.

    September 25, 2026

    Argentina’s poverty rate climbs to nearly one in three under Milei

    September 25, 2026

    2027 : LE BAROMÈTRE DU REJET – POLITICO

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.