Cloudflare Patched Data Exposure Vulnerability

A storage allocator flaw allowed cross-tenant data recovery on container infrastructure.

Updated on Oct. 5, 2026 in Cybersecurity

Isometric editorial illustration of a modular server storage array with cooling fins, representing cloud infrastructure data isolation.
Cloudflare has fully remediated a security vulnerability in its container storage infrastructure that previously allowed for cross-tenant data recovery. AI Illustration. Upload story photo >

Live Poll

Do you trust cloud providers to protect your data from other customers on shared infrastructure?

Cloudflare remediated a security vulnerability that allowed customers to recover residual data from other tenants on its container infrastructure. The issue was disclosed by researchers on September 4, 2026, and fully mitigated by September 19, 2026.

Why it matters

The flaw highlights the risks associated with performance-driven thin-block storage configurations where zeroing is skipped to save compute cycles. Security researchers successfully accessed foreign database pages and directory structures, demonstrating a critical breakdown in container isolation.

The vulnerability occurred in pools utilizing a 64 KiB thin-block size. During testing, researchers identified 2,700 distinct foreign directory inodes across 5,614 total testable blocks.

The players

Cloudflare

A provider of content delivery, cloud security, and serverless compute services through its Workers platform.

The details

The vulnerability stemmed from a thin-provisioning configuration that skipped the zeroing of newly allocated blocks during storage reuse. Researchers identified these unmapped regions by analyzing ext4 directory block checksums—mathematical values used to verify data integrity—to distinguish foreign data from their own containers. Cloudflare addressed the flaw by clearing all active container disks and flushing host image caches across four continents to ensure complete data sanitization.

Timeline

  1. September 4, 2026: Researchers reported the vulnerability to Cloudflare.

  2. September 7, 2026: Runtime fix rollout completed.

  3. September 14, 2026: Cloudflare awarded the bug bounty to researchers.

  4. September 19, 2026: Cleanup of all container disks and caches completed.

The Tech Race

This incident underscores the ongoing trade-off between infrastructure performance and multi-tenant isolation in serverless computing. Cloudflare Workers container architecture must balance the speed of thin-provisioned storage with the rigorous data separation required for secure cloud operations.

The vulnerability affected specific Workers Paid accounts using impacted container pools, though Cloudflare found no evidence of external malicious exploitation. Users do not need to take manual action as the company has completed the necessary host sanitization and runtime patching.

The takeaway

This case highlights the fragility of shared storage layers in modern cloud infrastructure and the importance of checksum-based security auditing. Developers should monitor Cloudflare's platform updates to verify if additional storage hardening measures are implemented following this incident.

Further reading

For broader trends in cloud security, explore our latest coverage in Cybersecurity.

Live Poll

Do you trust cloud providers to protect your data from other customers on shared infrastructure?