How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Cloudflare patched a cross-tenant data exposure flaw in its Containers service after a researcher reported residual disk block leakage. The fix removes the skip_block_zeroing option in dm-thin, eliminating the risk of one customer reading leftover data from another. No evidence of exploitation was found and no customer changes are required.

Cover image for How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

A flaw in the storage layer allowed containers to read leftover data from shared disk blocks. Cloudflare explained that the thin provisioning system skipped zeroing blocks before reassigning them to new workloads. This meant smaller writes could leave previous customer data intact on the host. The issue impacted Cloudflare Containers and the related Sandboxes service. A researcher from Accomplish demonstrated the behavior with a Workers Paid account in September 2026. Residual data was not guaranteed to exist on all instances or targets. No customer action is necessary because the provider has already deployed the fix. The system update removed the option that prevented block zeroing across the fleet. Company telemetry showed no signs that anyone exploited the weakness for malicious purposes.