Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Cross‑Tenant Data Exposure Vulnerability in Cloudflare Containers Fixed After Responsible Disclosure

Cloudflare patched a storage‑allocation flaw that could let one tenant read leftover disk blocks from another tenant’s container. No data was compromised, but the issue underscores the need for continuous configuration assurance and auditable evidence of remediation.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 blog.cloudflare.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
blog.cloudflare.com

Cross‑Tenant Data Exposure Vulnerability in Cloudflare Containers Fixed After Responsible Disclosure

What Happened — Cloudflare identified a storage‑allocation misconfiguration in its multi‑tenant Containers and Sandboxes service that could let a tenant read residual disk blocks from a previous container on the same host. The flaw was responsibly disclosed by a researcher, patched fleet‑wide, and no customer data was found to be compromised.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification that storage‑provisioning controls enforce strict data segregation across tenants.
  • Highlights the importance of real‑time configuration monitoring and auditable evidence that remediation actions have been applied.
  • Aligns with the control objective of “segregated data handling and secure storage” that underpins many frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected – Cloud service providers offering shared‑infrastructure containers; SaaS platforms that run customer workloads on multi‑tenant hosts.

Recommended Actions – Review your container‑orchestration storage settings for block‑zeroing; enable continuous monitoring of storage‑layer configurations; capture remediation evidence for audit readiness. Source: https://blog.cloudflare.com/containers-cross-tenant-vulnerability/

Technical Notes – The issue stemmed from the skip_block_zeroing option in Linux dm‑thin thin provisioning, which left 64 KiB blocks partially un‑zeroed when reassigned. Exploitation required a tenant with a Workers Paid account to write small aligned blocks and read leftover data. No CVE was assigned; Cloudflare issued a vendor patch. Source: https://blog.cloudflare.com/containers-cross-tenant-vulnerability/

📰 Original Source
https://blog.cloudflare.com/containers-cross-tenant-vulnerability/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →