On 24 September 2026, Cloudflare detailed a vulnerability in Containers and Sandboxes reported on 4 September by researcher Oren Yomtov. A Workers Paid customer could recover residual storage blocks from another workload placed on the same host.
What Cloudflare fixed
The issue involved reused thin-provisioned blocks in a shared pool. With skip_block_zeroing enabled, a reassigned block could retain part of its old contents when the new workload did not write the whole area.
Cloudflare says it fixed the runtime, rolled the change across the fleet and cleared old snapshots. It found no malicious exploitation beyond authorized research and internal validation.
A specific scenario, not a general leak
The scenario required a Workers Paid account and favorable placement. Researchers could not choose a victim, workload or host, and residual data was not guaranteed to be present.
Those limits do not make the issue irrelevant: they describe the risk accurately without claiming that every customer’s data was exposed.
Data to inventory
Teams using Containers or Sandboxes should list secrets, tokens, configuration files and temporary data present in workloads before the fix. Pay particular attention to environment variables and temporary SQLite databases.
Cloudflare’s fix reduces the infrastructure risk. It cannot prove that every secret in a workload remained confidential if other evidence suggests access.
If exposure is possible
If a workload held a sensitive secret and the organization cannot rule out reading, prepare rotation, review logs and preserve useful evidence. Do not replace a key merely to erase a trace; coordinate rotation with the investigation.
Also avoid copying secrets into tickets or incident notes. The remediation record should identify the object and action without reproducing the secret value.
How Soclyde fits
Soclyde does not patch Cloudflare Containers and cannot verify a workload’s history. It can help keep distinct secrets in a local-first encrypted vault and find the ones to rotate after an assessment.
That approach limits centralized copies of access data without turning the vault into proof of infrastructure integrity.
Key takeaway
Cloudflare fixed an isolation flaw that could expose residual blocks, with no malicious exploitation found according to the company. Inventory workload secrets and prepare rotation if needed. See the secure password generator or contact Soclyde.



