2026 Cloudflare Containers/Sandboxes — cross-tenant residual disk blocks (mitigated Sep 19)
Data compromised
Potential residual filesystem metadata, directory structures, database pages, .env/credential files, SQLite DBs, Chromium profiles from other customers’ containers. Researchers’ evaluation returned aggregate counts only — Cloudflare says no real customer data was exfiltrated in that test. recordsAffected 0.
Technical writeup
Verified vendor disclosure — Cloudflare fixed a Containers/Sandboxes isolation flaw reported via HackerOne Sep 4, 2026 (researcher Oren Yomtov / Accomplish). Deleted container root disks returned physical blocks to a multi-tenant pool without zeroing; writing 4 KiB into a new disk could leave ~60 KiB of prior-tenant residual data readable. Residual material observed on most tested placements. Mitigations (disable skip-zeroing, retire disks, clear snapshots) completed by Sep 19, 2026; customers need no action. Evaluation scripts did not dump actual disk contents. recordsAffected 0; companyConfirmed true.
Root cause
Shared thin-volume pool skipped zeroing reused 64 KiB blocks; Workers Paid tenant could recover residual data from prior containers on same host (Cloudflare blog).