Global technology recovery · 2026-09-24
Cloudflare fixed a cross-tenant storage flaw in Containers and Sandboxes; the root cause shows why deleted cloud blocks must be zeroed before reuse.
Key takeaways
- Cloudflare Containers and Sandboxes
- dm-thin pool used skip_block_zeroing
- Cloudflare says none required
Cloudflare disclosed that it fixed a cross-tenant data-exposure flaw in Cloudflare Containers and Sandboxes after researchers showed that a new workload could recover residual disk bytes left by another customer. The company says the fleet was remediated, old cached snapshots were cleared by 19 September, and retained telemetry showed no malicious exploitation.
The incident was not a conventional virtual-machine escape. Cloudflare traced it to Linux device-mapper thin provisioning configured to skip block zeroing. That distinction matters because the boundary failed below the application layer: isolation looked intact while reused storage still carried fragments from an earlier tenant.
How the Cloudflare Containers gap worked
Cloudflare assigns each container a writable virtual disk backed by shared physical storage. When a container was deleted, its physical blocks returned to a pool. With skip_block_zeroing enabled, a reassigned 64 KiB block was not cleared before use.
If the new tenant wrote a smaller amount—Cloudflare’s example used about 4 KiB—only that portion changed. A raw read of the virtual disk could expose the remaining bytes. Researchers recovered structured files during controlled testing, but could not choose a specific customer, workload or host.
This is why deleting a logical volume is not the same as sanitising its underlying media. The lesson complements our report on CISA’s Linux kernel deadline: infrastructure operators must verify the full data lifecycle, not only the software version at the edge.
What Cloudflare changed
Cloudflare removed the zeroing bypass, rolled the change across the fleet, retired pre-mitigation root disks and deleted cached image-layer snapshots created before the fix. It also built a test that deliberately writes known blocks and confirms they return as zeros when reused.
The company says customers do not need to change configuration. That is narrower than saying there was no risk: the technique created a confidentiality path, but Cloudflare reports no evidence that anyone beyond the researchers and its engineers used it. Organisations should record both facts rather than collapse them into either “breach” or “no issue.”
Security teams can apply the same discipline to endpoint advisories such as Android’s September security update: separate potential impact, observed exploitation and required action. Here, potential exposure was real, observed malicious exploitation was not found, and remediation was service-side.
Why this matters beyond one platform
Multi-tenant clouds reuse resources constantly. Performance optimisations that remove clearing work can silently weaken the assumption that one customer never sees another’s data. The strongest control is a repeatable test at the moment storage changes ownership, backed by telemetry that detects raw reads inconsistent with normal workloads.
Cloudflare’s disclosure also offers a useful procurement question: can a provider explain how ephemeral storage is destroyed, reallocated and audited? Controls around AI workloads, like those in F5’s workforce AI security launch, still depend on lower layers behaving as promised.
The defensible conclusion is precise: Cloudflare Containers had a storage-isolation defect, the vendor says it is fixed, and there is no evidence in retained telemetry of malicious abuse. The broader consequence is that “ephemeral” must describe verified erasure, not merely a deleted control-plane object.
Facts at a glance
| Disclosure | 24 September 2026 |
|---|---|
| Affected services | Cloudflare Containers and Sandboxes |
| Root cause | dm-thin pool used skip_block_zeroing |
| Fix rollout | Completed 7 September; cleanup completed 19 September |
| Customer action | Cloudflare says none required |
Frequently asked questions
Was customer data confirmed stolen?
No. Cloudflare says it found no evidence of malicious exploitation in the telemetry it retained.
How did the Cloudflare Containers flaw work?
A newly assigned 64 KiB storage block could retain bytes from a previous tenant when only part of the block was overwritten.
Do customers need to patch anything?
Cloudflare says the service-side remediation is complete and no customer configuration change is required.
Recovery article using the event’s actual public-disclosure date. Claims and limits are recorded in the research ledger.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



