← Home
CYBERSECURITY

Cloudflare patches cross-tenant data leak in Containers service

October 4, 2026 Bill Toulas

How the isolation failure occurred in shared hosting

Cloudflare has resolved a security flaw in its Containers and Sandboxes platform that exposed residual customer data to other users on shared infrastructure. The vulnerability affected customers with Workers Paid accounts, enabling unauthorized access to leftover data from neighboring containers hosted on the same physical server. The issue was identified and patched internally before any public exploitation was reported, according to the company's disclosure on September 27, 2026. Cloudflare confirmed the fix was deployed across its global network to prevent further risk.

The flaw stemmed from insufficient memory isolation between tenant environments in the Containers runtime, where data remnants from prior workloads were not fully cleared before reuse. This allowed a malicious or curious user with access to the Workers Paid tier to potentially scrape sensitive information such as environment variables, tokens, or application state from other customers’ functions. Cloudflare emphasized that the vulnerability required specific conditions to exploit and that no evidence of active attacks was found during their investigation. The company worked with internal security teams to reproduce the scenario and validate the effectiveness of the remediation.

What steps did Cloudflare take to prevent recurrence?

The Containers service relies on lightweight virtualization to run customer code efficiently across Cloudflare’s edge network. Under normal operation, each tenant’s workload runs in an isolated sandbox designed to prevent cross-access. However, a gap in the cleanup process between container lifecycles meant that memory pages were not always zeroed out or reallocated securely before being assigned to a new user. This created a window where residual data could persist long enough to be read by another tenant’s process. Cloudflare engineers traced the issue to a race condition in the resource recycling module, which has since been tightened with stricter validation and memory scrubbing protocols.

Following the discovery, Cloudflare implemented enhanced memory sanitization routines that now run automatically after every container termination, regardless of workload type or duration. The company also increased monitoring for anomalous memory access patterns across its infrastructure to detect similar issues earlier. Affected customers were not required to take any action, as the fix was applied transparently at the platform level. Cloudflare reiterated its commitment to multi-tenant security, noting that regular third-party audits and internal red team exercises continue to test the resilience of its isolation boundaries. The incident underscores the ongoing challenges in securing shared compute environments at scale.

Was any customer data actually stolen or misused due to this flaw? Cloudflare stated there is no evidence that the vulnerability was exploited in the wild or that any data was accessed, copied, or leaked by unauthorized parties during the time it was present.

Frequently Asked Questions

Do users need to rotate keys or change passwords after this patch? No, Cloudflare confirmed that no customer action is required, as the flaw was addressed server-side and no breach of customer secrets has been detected.

How does this affect the reliability of Cloudflare Workers for sensitive workloads? The company maintains that Workers remains secure for processing sensitive data, and this fix reinforces the isolation guarantees expected from its platform.

Read full article on Tech Site News →