Trusence Every claim has a source
Last updated 5 October 2026 Search Türkçe
← All stories
Security

Cloudflare fixes container bug that could expose leftover data between tenants

The fix closes a storage-layer leak in Workers Paid containers and shows that isolation still depends on what happens beneath microVM boundaries.

Cloudflare fixed a cross-tenant data exposure bug in its Containers service after a researcher found that reused thin-provisioned disk blocks could leak leftover bytes between customers on shared hosts. The issue affected Workers Paid containers running inside Firecracker microVMs and came from dm-thin using 64 KiB blocks with skip_block_zeroing, which left data behind when new writes reused old storage. Cloudflare says it found no evidence of malicious exploitation, and the researchers did not show another customer’s data being modified or any availability impact. The report arrived on September 4, Cloudflare completed the rollout on September 7, and it later retired running container disks and cleared host image caches, finishing that cleanup on September 19. The disclosure also landed near new isolation-focused launches from Microsoft Azure Container Apps Sandboxes and Google GKE Pod snapshots, underscoring that storage-layer behavior still matters beneath microVM and sandbox claims.

Why it matters

For customers sharing Cloudflare’s container hosts, the issue meant leftover bytes from earlier writes could surface in another tenant’s storage. Cloudflare says it found no evidence of malicious exploitation, but the episode shows that container isolation is not just about the microVM layer; storage behavior can still affect what data stays private.

Sources

  • InfoQ