Cloudflare Addresses Cross-Tenant Data Exposure Vulnerability in Containers
Cloudflare has remediated a vulnerability in Cloudflare Containers and Cloudflare Sandboxes, reported through the company's bug bounty program.
On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers) through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and there is no evidence that customer data has been compromised.
The vulnerability allowed a customer with a Workers Paid account to recover residual disk blocks previously used by Containers on the same host. However, the technique could not target a particular customer, workload, host, or data, and residual data was not guaranteed to be present.
Cloudflare applied a fix across the Containers fleet, with no customer-side configuration changes required. The company identified no evidence of malicious exploitation in historical disk-I/O telemetry. Activity attributed to the reported technique came from the researchers and Cloudflare engineers conducting authorized validation.
Cloudflare opened a security incident and confirmed the production setup that caused the flaw. The timeline of the incident includes:
- September 4, 21:27 UTC: Cloudflare merged the runtime fix and its reuse test.
- September 4, 22:03 UTC: Cloudflare merged the changes for new and live pools.
- September 4, 23:15 UTC: Cloudflare started rolling out the changes.
- September 7, 06:13 UTC: Cloudflare completed rolling out the changes and began clearing old pool data.
- September 14, 10:50 UTC: The researchers reported that their proof of concept had stopped working.
- September 14, 12:52 UTC: Cloudflare awarded the researcher a bounty.
- September 19, 15:03 UTC: Cloudflare completed cleanup of all pre-mitigation cached snapshots across the affected fleet.
This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped Cloudflare validate the issue and respond quickly.
Source: cloudflare
