Cloudflare remediated a cross-tenant data-disclosure flaw in Cloudflare Containers and Cloudflare Sandboxes after Oren Yomtov of Accomplish responsibly reported it on September 4. Linux dm-thin storage pools had been configured with skip_block_zeroing, allowing a newly allocated 64 KiB block to retain as much as 60 KiB of data from a deleted container after a 4 KiB write. A Workers Paid customer could potentially recover residual filesystem metadata, database pages, or application data from a prior workload sharing the same host.
An attacker could not select a target tenant, host, or active disk, limiting the exposure to remnants on previously used storage. Cloudflare removed the unsafe storage configuration, retired and recreated existing disks and cached snapshots, and completed fleet cleanup on September 19. The company said it found no evidence of malicious exploitation or customer data compromise.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Cloudflare completed cleanup of cached dm-thin snapshots created before mitigation, after draining hosts, restarting virtual machines, clearing image caches, and recreating disks and cached layers with zeroed allocations.
The researchers independently confirmed that their proof of concept no longer functioned after Cloudflare's runtime mitigation.
Cloudflare completed rollout of a configuration change removing dm-thin's unsafe skip_block_zeroing setting across its Containers fleet, restoring zeroing of newly allocated blocks.
Oren Yomtov of Accomplish responsibly reported a cross-tenant data-disclosure vulnerability in Cloudflare Containers and Cloudflare Sandboxes through Cloudflare's HackerOne program. The flaw could expose residual data from previously deleted container volumes when reused dm-thin blocks were not zeroed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.