← Blog · · df00tech

Cloudflare Patches Cross-Tenant Data Exposure in Containers/Sandboxes Service

security-news technique

What happened

Cloudflare fixed a vulnerability in its Containers and Sandboxes offering that allowed customers on a Workers Paid plan to recover residual data left behind by other customers' containers running on the same physical host, according to a report from BleepingComputer. The flaw stemmed from insufficient isolation of container state between tenants sharing underlying host infrastructure.

Why it matters

This is a cross-tenant isolation failure in a multi-tenant cloud compute service — one of the more serious classes of cloud provider vulnerabilities, since it undermines the core promise that customer workloads and data are segregated from each other. Organizations using Cloudflare Workers Paid with Containers/Sandboxes could potentially have had residual data (e.g., leftover memory, filesystem, or execution artifacts) exposed to other tenants on shared hardware. At this stage, no detail has been reported on whether the flaw was exploited in the wild, and no scope of affected customers has been disclosed.

What defenders should watch for

  • Review Cloudflare account audit logs for unusual container/sandbox provisioning or access patterns, particularly around the disclosure window.
  • Treat any secrets or sensitive data processed inside Cloudflare Containers/Sandboxes prior to the fix as potentially exposed, and rotate credentials as a precaution if your risk tolerance warrants it.
  • For any multi-tenant compute service (not just Cloudflare), maintain an inventory of what sensitive data is processed in shared-host environments, and prefer dedicated/isolated hosting for highly sensitive workloads where the provider offers it.
  • Monitor vendor security advisories and disclosure channels for follow-up details, including any confirmation of exploitation or affected customer notifications.

Developing story

Details here are limited to what Cloudflare and BleepingComputer have disclosed so far; no CVE identifier, exploitation status, or full technical root cause has been published at this time. We will track this item for updates. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.