SOCLYDE logo
Current languageEN
Cybersecurity newsCloudContainersData

Cloudflare containers: cross-tenant isolation flaw fixed

Cloudflare explains how residual storage blocks could cross tenant boundaries and says it fixed the issue without evidence of malicious exploitation.

By Soclyde Team

Hands compare storage blocks in a technical workshop

In summary

  • An incomplete zeroing process could expose residual blocks from a previous workload in Cloudflare Containers.
  • Cloudflare says it deployed a fix and found no evidence of malicious exploitation.
  • A provider fix does not remove the need to review secrets held by affected workloads.

Explore next

Soclyde resources

Article contents

On 24 September 2026, Cloudflare detailed a vulnerability in Containers and Sandboxes reported on 4 September by researcher Oren Yomtov. A Workers Paid customer could recover residual storage blocks from another workload placed on the same host.

What Cloudflare fixed

The issue involved reused thin-provisioned blocks in a shared pool. With skip_block_zeroing enabled, a reassigned block could retain part of its old contents when the new workload did not write the whole area.

Cloudflare says it fixed the runtime, rolled the change across the fleet and cleared old snapshots. It found no malicious exploitation beyond authorized research and internal validation.

A specific scenario, not a general leak

The scenario required a Workers Paid account and favorable placement. Researchers could not choose a victim, workload or host, and residual data was not guaranteed to be present.

Those limits do not make the issue irrelevant: they describe the risk accurately without claiming that every customer’s data was exposed.

Data to inventory

Teams using Containers or Sandboxes should list secrets, tokens, configuration files and temporary data present in workloads before the fix. Pay particular attention to environment variables and temporary SQLite databases.

Cloudflare’s fix reduces the infrastructure risk. It cannot prove that every secret in a workload remained confidential if other evidence suggests access.

If exposure is possible

If a workload held a sensitive secret and the organization cannot rule out reading, prepare rotation, review logs and preserve useful evidence. Do not replace a key merely to erase a trace; coordinate rotation with the investigation.

Also avoid copying secrets into tickets or incident notes. The remediation record should identify the object and action without reproducing the secret value.

How Soclyde fits

Soclyde does not patch Cloudflare Containers and cannot verify a workload’s history. It can help keep distinct secrets in a local-first encrypted vault and find the ones to rotate after an assessment.

That approach limits centralized copies of access data without turning the vault into proof of infrastructure integrity.

Key takeaway

Cloudflare fixed an isolation flaw that could expose residual blocks, with no malicious exploitation found according to the company. Inventory workload secrets and prepare rotation if needed. See the secure password generator or contact Soclyde.

Frequently asked questions

Was customer data exposed?

Cloudflare says it found no evidence that customer data was compromised or that a malicious actor exploited the vector. The scenario required a Workers Paid account and did not allow researchers to choose a victim, workload or host.

Do customers need to change their configuration?

Cloudflare says the fix requires no customer action. Teams should still inventory secrets and sensitive data that may have been present in workloads before remediation.

How can a deleted block still contain data?

In the described mechanism, reassigned physical blocks were not always cleared before becoming available to another workload. A partial write could leave an older portion intact.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading