AI Weekly Malaysia

Back to items Summaries

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

ID
28134
Status
summarized
Published
24 Sep 2026, 11:00 PM
Fetched
24 Sep 2026, 11:35 PM
Provider
Cloudflare Blog
Category
infrastructure
Original URL
https://blog.cloudflare.com/containers-cross-tenant-vulnerability/
Source URL
https://blog.cloudflare.com/rss/

Summary

Score
6.5
Created
24 Sep 2026, 11:35 PM
Tags
Audience
developersai_ml_learnerssaas_founders

What happened

On September 4, 2026, security researcher Oren Yomtov from Accomplish reported a bug-bounty finding that a customer on a Workers Paid account could recover residual disk blocks previously used by other customers' Cloudflare Containers on the same host. The cause was dm-thin thin provisioning with a 64 KiB thin-block size and the skip_block_zeroing option, so when a deleted container volume's blocks were reassigned, a partial write left the rest of the block holding prior data. Cloudflare says it remediated the Containers fleet with no customer-side configuration changes, found no evidence of malicious exploitation, and notes the technique could not target a specific customer, workload, host, or data.

Why it matters

If you run Cloudflare Sandboxes (built on Containers) for AI agent code execution, there is nothing to change on your side, but the underlying lesson transfers: any self-hosted sandbox stack using Firecracker plus dm-thin should check whether skip_block_zeroing (or an equivalent zeroing bypass) is enabled, because it trades write throughput for the risk that a deleted tenant volume's blocks are handed to another tenant unzeroed. If you build on a platform with this class of isolation, the decision to make now is whether you need per-tenant evidence of block zeroing or separate storage pools, rather than assuming volume deletion equals data destruction.

Discussion angle

Zeroing blocks on reassignment costs I/O, which is presumably why skip_block_zeroing was set — so where is the line between acceptable multi-tenant performance tuning and a cross-tenant data exposure, and would your own agent-sandbox stack survive the same test?

Top