Cloudflare Patched Data Exposure Vulnerability

The company fixed a flaw that allowed certain users to recover residual data from other customers' containers.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of modular server storage drive blocks, representing systematic data infrastructure.
Cloudflare remediated a data exposure vulnerability on September 19, 2026, which had allowed cross-tenant access to residual disk storage. AI Illustration. Upload story photo >

Live Poll

Do you trust cloud providers to protect your data from other customers on shared infrastructure?

Cloudflare completed the remediation of a cross-tenant data exposure vulnerability on September 19, 2026. The issue allowed customers on Workers Paid accounts to access residual disk blocks from other users due to a configuration error in the storage allocator.

Why it matters

The vulnerability occurred because the infrastructure utilized a performance optimization that skipped zeroing out block data upon reuse. This failure in the storage layer allowed for the potential exposure of directory structures and database pages between different tenants.

The flaw affected storage pools using a 64 KiB thin-block size. Researchers successfully identified foreign data by utilizing ext4 directory block checksums to analyze the unmapped regions.

The players

Cloudflare

Cloudflare is a global provider of content delivery networks, cybersecurity services, and cloud infrastructure.

The details

Cloudflare retired all active container disks and cleared host image caches to sanitize the environment after the bug was reported. While the vulnerability potentially exposed sensitive information like SQLite databases, the company confirmed there was no evidence that malicious actors exploited the flaw.

Timeline

  1. Researchers reported the vulnerability to Cloudflare on September 4, 2026.

  2. The company completed its runtime fix rollout on September 7, 2026.

  3. Cloudflare issued a bug bounty to the reporting researchers on September 14, 2026.

  4. All container disk cleanup and host sanitization processes concluded on September 19, 2026.

The Tech Race

This incident underscores the complex security challenges inherent in multi-tenant container infrastructure, where performance optimizations often clash with data isolation requirements. As platforms push for faster storage allocation, they must balance the speed of block reuse with the risks of data leakage between users.

Users of cloud-based container services should prioritize implementing end-to-end encryption to protect data even if infrastructure-level isolation fails. Customers do not need to take immediate action, as Cloudflare has already sanitized the affected disks and caches.

The takeaway

This event demonstrates that even advanced infrastructure providers can face risks when optimizing for storage performance at the expense of strict data zeroing. Security researchers play a critical role in identifying these architectural flaws before they can be leveraged by malicious entities.

Further reading

For more information on infrastructure security, visit our Cybersecurity section.

Live Poll

Do you trust cloud providers to protect your data from other customers on shared infrastructure?