Cloudflare Patches Cross-Tenant Data Leak in Containers Service
Cloudflare fixes a cross-tenant vulnerability in its Containers and Sandboxes service that allows customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. The flaw is reported on September 4 through HackerOne by Oren Yomtov, a security researcher at Accomplish, and could expose files including directory listings, SQLite databases, Chromium profiles, .env files, and credentials.
The issue originates in a shared storage pool configured to skip zeroing of reused 64 KiB blocks. When a container's root disk is deleted, its physical blocks return to a pool shared across multiple customer accounts. By writing only 4 KiB to an unused region of a new container's disk, a researcher can cause a reused 64 KiB block to be allocated, leaving the remaining 60 KiB readable and potentially containing a previous customer's data.
Testing finds residual material on 18 of 24 container placements and across 20 of 22 underlying nodes, including complete SQLite databases and directory structures. Cloudflare notes that an attacker could not control a victim or host, nor read an actively attached disk, and the researchers' scripts only return aggregate counts rather than actual disk contents, limiting real-world exposure.