E-Ink News Daily

← Back to list

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Cloudflare disclosed a cross-tenant data exposure vulnerability in its Containers and Sandboxes services, reported by security researcher Oren Yomtov via their bug bounty program. The flaw allowed a Workers Paid account holder to recover residual disk blocks from containers previously hosted on the same multi-tenant server, though exploitation was random and non-targeted. Cloudflare has fully remediated the issue across its fleet with no evidence of customer data compromise or unauthorized exploitation.

Background

Cloudflare Containers is a platform service that runs workloads on multi-tenant infrastructure using Firecracker VMs and Linux device mapper thin provisioning for disk management. Cross-tenant data exposure vulnerabilities in cloud container services remain a significant concern given the shared infrastructure model.

Source
Lobsters
Published
Oct 6, 2026 at 07:03 AM
Score
7.0 / 10