Technology

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Bleeping Computer September 27, 2026 5 views

Advertisement

Cloudflare has announced a fix for a security vulnerability in its Containers and Sandboxes that could have allowed customers with a Workers Paid account to recover residual data from other customers’ containers running on the same physical host.

The flaw, identified as a cross‑tenant data leakage issue, stemmed from incomplete wiping of data when a container was shut down. Because the containers share the same underlying hardware, a malicious or careless user could potentially read leftover files from another tenant’s environment.

Only users who subscribed to the paid tier of Cloudflare Workers were at risk, as the vulnerability was specific to the paid containers and sandbox infrastructure. The issue did not affect the free tier or other Cloudflare services.

Cloudflare released a patch that ensures all residual data is securely erased before a container is de‑allocated. The company has updated its documentation and advised all affected customers to apply the update immediately to eliminate the risk of unintended data exposure.

While the company has not reported any confirmed incidents of data being accessed through the flaw, it has urged users to review their security settings and to keep their Workers environments up to date with the latest patches.

<small>Source: Bleeping Computer — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement