Cloudflare fixes Containers flaw that could have exposed other customers' data

· CyberSecurity

TLDR

  • Cloudflare fixed a bug in its Containers service that could have let a customer on the Workers Paid plan recover leftover data from other customers' containers running on the same physical server.
  • The flaw stemmed from a shared storage pool that skipped zeroing out reused 64 KiB blocks when a container's disk was deleted, leaving up to 60 KiB of a previous tenant's data readable inside a new container.
  • Researcher Oren Yomtov of Accomplish reported the bug through HackerOne on 4 September; testing found residual data in 18 of 24 container placements and on 20 of 22 underlying nodes.
  • Cloudflare says it found no evidence any customer data was actually exposed via this method in production, and finished remediation by 19 September.

A researcher found that Cloudflare's Containers service, which runs containerised apps on the Workers Paid plan, stored container disks in a shared pool that did not zero out reused 64 KiB storage blocks after a container was deleted.1 By writing just 4 KiB of data into an unused region of a new container's disk, an attacker could trigger allocation of one of these reused blocks and read the remaining 60 KiB of a previous tenant's leftover data, which could include directory structures, database pages, and complete SQLite databases.1

Oren Yomtov, a researcher at Accomplish, reported the flaw through HackerOne on 4 September.1 Testing across 24 container placements on 22 underlying nodes found residual material in 18 of the placements and on 20 of the nodes, including .env files and Chromium browser profiles, though the researchers only counted matches rather than extracting live data, and attackers had no control over whose container they landed next to and could not read an actively attached disk.1 Cloudflare said it reviewed its logs, telemetry, and historical data and found no evidence that any customer's data was exposed through this method in production, and completed remediation, including removing the setting that skipped block zeroing and retiring existing container disks, by 19 September.1

Why it matters: the flaw shows that a routine storage optimisation, skipping a zeroing step to save time, can silently break the isolation multi-tenant cloud platforms depend on, so even though Cloudflare found no evidence of real-world exposure here, similar shared-storage shortcuts elsewhere could be leaking one customer's files to another right now.

Sources

  1. Cloudflare fixes Containers cross-tenant flaw exposing customer data (BleepingComputer)