Cloudflare Patched Data Exposure Vulnerability
A storage allocator flaw allowed cross-tenant data recovery on container infrastructure.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Do you trust cloud providers to protect your data from other customers on shared infrastructure?
Cloudflare remediated a security vulnerability that allowed customers to recover residual data from other tenants on its container infrastructure. The issue was disclosed by researchers on September 4, 2026, and fully mitigated by September 19, 2026.
Why it matters
The flaw highlights the risks associated with performance-driven thin-block storage configurations where zeroing is skipped to save compute cycles. Security researchers successfully accessed foreign database pages and directory structures, demonstrating a critical breakdown in container isolation.
The vulnerability occurred in pools utilizing a 64 KiB thin-block size. During testing, researchers identified 2,700 distinct foreign directory inodes across 5,614 total testable blocks.
The players
Cloudflare
A provider of content delivery, cloud security, and serverless compute services through its Workers platform.
The details
The vulnerability stemmed from a thin-provisioning configuration that skipped the zeroing of newly allocated blocks during storage reuse. Researchers identified these unmapped regions by analyzing ext4 directory block checksums—mathematical values used to verify data integrity—to distinguish foreign data from their own containers. Cloudflare addressed the flaw by clearing all active container disks and flushing host image caches across four continents to ensure complete data sanitization.
Timeline
September 4, 2026: Researchers reported the vulnerability to Cloudflare.
September 7, 2026: Runtime fix rollout completed.
September 14, 2026: Cloudflare awarded the bug bounty to researchers.
September 19, 2026: Cleanup of all container disks and caches completed.
The Tech Race
This incident underscores the ongoing trade-off between infrastructure performance and multi-tenant isolation in serverless computing. Cloudflare Workers container architecture must balance the speed of thin-provisioned storage with the rigorous data separation required for secure cloud operations.
The vulnerability affected specific Workers Paid accounts using impacted container pools, though Cloudflare found no evidence of external malicious exploitation. Users do not need to take manual action as the company has completed the necessary host sanitization and runtime patching.
The takeaway
This case highlights the fragility of shared storage layers in modern cloud infrastructure and the importance of checksum-based security auditing. Developers should monitor Cloudflare's platform updates to verify if additional storage hardening measures are implemented following this incident.
Further reading
For broader trends in cloud security, explore our latest coverage in Cybersecurity.
Live Poll
Do you trust cloud providers to protect your data from other customers on shared infrastructure?









