Cloudflare has fixed a vulnerability that allowed paying customers to recover data left behind by other tenants on shared container infrastructure.
Cloudflare’s Sandbox documentation describes uses including AI agents, data analysis, interactive development environments and build pipelines.
The same documentation describes an outbound traffic mechanism that can keep credentials in a Worker and add authentication headers outside the sandbox.
That approach does not repair a provider’s storage isolation flaw.
Shared cloud infrastructure needs to protect the next customer from the previous customer’s data just as reliably as it separates their running applications.
Cloudflare has fixed a vulnerability that allowed paying customers to recover data left behind by other tenants on shared container infrastructure. In its September 24 disclosure, the company said it found no evidence of malicious exploitation in available historical telemetry and that customers need take no action.
The issue, detailed in Cloudflare’s incident report, affected the separation between customers’ stored data. It highlights how the security of hosted computing depends on what happens to storage after a workload finishes, as well as the protections surrounding it while it runs.
Research Identifies Sensitive File Exposure
In Accomplish’s account of the discovery, principal security researcher Oren Yomtov said the team found a disk isolation flaw that allowed a sandbox to read other customers’ files. The reported material included directory listings, SQLite databases, Chromium profiles, environment configuration files and credential files.
Accomplish said Cloudflare Sandboxes and Browser Run shared the affected disk implementation. The researchers reported the issue on September 4 and worked with Cloudflare on a joint technical explanation.
Those categories make the finding significant for organisations running applications that handle confidential information. Depending on their contents, configuration and credential files can reveal application settings or access secrets. Browser profiles and databases can hold information generated during a user session or application workflow. These are potential consequences of exposing such files; their presence alone does not establish that a usable credential was stolen or an account compromised.
The research demonstrates a confidentiality failure. It should not be treated as evidence that criminals harvested the same information.
How Storage Reuse Creates an Exposure
Cloudflare attributed the flaw to the skip_block_zeroing setting: a 4 KiB write could leave 60 KiB of an allocated 64 KiB block containing earlier data. Attackers could not choose a victim or read an actively attached disk; access depended on placement and block reuse.
The Linux kernel’s thin-provisioning documentation describes the underlying storage system and explicitly identifies skip_block_zeroing as an option that skips clearing newly provisioned blocks. Thin provisioning allows virtual storage to be backed by physical capacity as needed, with multiple volumes managed through a storage pool.
The security distinction is between allocating storage and sanitising its contents. Giving a block to a new workload changes who can access it. Clearing that block determines whether information from an earlier workload remains visible.
For example, writing a small amount of new information does not inherently replace every byte in a larger storage allocation. If the unwritten portion contains old data, a later reader may encounter content it never created. A filesystem’s view of unused space and the underlying device’s actual contents are therefore different things.
Linux’s documentation also treats discarding storage mappings and passing discard requests to underlying devices as separate configurable behaviours. That distinction matters when assessing deletion guarantees: releasing an allocation, removing a mapping and ensuring that its previous contents cannot be recovered are separate engineering concerns.
Why Virtual Machines Do Not Resolve Every Isolation Risk
Firecracker’s design documentation explains how its microvirtual machines combine lightweight execution with virtual-machine isolation. It describes several defensive layers, including KVM, restricted system calls, resource controls and a jailer process that reduces privileges.
However, a virtual machine also needs storage supplied by its host. Firecracker’s documentation describes guest block devices backed by host-side files, illustrating the dependency between the virtualisation boundary and the resources a platform attaches to it.
The architectural lesson is that a workload can receive information it should never see through an otherwise legitimate resource. Protecting the host against guest code and ensuring that a guest’s disk contains only authorised data are distinct responsibilities.
For security assessments, that means checking more than whether a workload can escape its execution environment. Storage preparation, reuse, snapshots and cleanup also belong within the isolation review. This is an inference from the architecture and disclosed failure mode, rather than evidence of an additional vulnerability.
Remediation Required More Than a Configuration Change
Cloudflare restored block zeroing and retired pre-fix container disks and cached image snapshots. Its rollout finished September 7, with snapshot cleanup completed September 19. The researchers confirmed their proof of concept stopped working.
The distinction between preventing new exposure and removing earlier unsafe state has wider operational significance. A configuration correction can change future behaviour while leaving existing resources untouched. Incident recovery therefore needs to account for the objects created before the correction, including reusable images and cached state.
For cloud customers evaluating a provider’s response, a useful question is whether remediation covers both future resource creation and previously created resources. A patch deployment date and a cleanup completion date can describe different stages of recovery.
Implications for AI Agents and Developer Platforms
The exposure is relevant to services that execute code on behalf of users. Cloudflare’s Sandbox documentation describes uses including AI agents, data analysis, interactive development environments and build pipelines. The platform supports command execution, file operations, background processes and persistent execution state.
Those capabilities explain why sandbox confidentiality matters alongside containment. A development environment can process source code; a data analysis session can load business records; an automated workflow can create intermediate files. These are examples of the information such applications may handle, not confirmed contents of the recovered material.
The same documentation describes an outbound traffic mechanism that can keep credentials in a Worker and add authentication headers outside the sandbox. Architecturally, keeping a secret outside an execution environment reduces the number of places where it can be exposed.
That approach does not repair a provider’s storage isolation flaw. It can, however, limit the sensitive material placed inside environments that routinely process untrusted code.
What the Findings Mean for Security Teams
The disclosure gives enterprise security teams a concrete issue to examine in supplier reviews: how shared infrastructure prevents information from surviving a change of tenant.
Questions about data deletion should cover the full resource lifecycle. What happens when an environment stops? Which snapshots or caches remain? At what point is reused capacity cleared? How is that behaviour tested against a workload deliberately looking for residual information?
Investigation findings also need careful interpretation. A statement that a provider found no evidence of malicious exploitation describes the result of its investigation. It does not turn a demonstrated exposure into a harmless condition, nor does the existence of the flaw establish that every customer suffered a breach.
The broader lesson is that isolation must hold across time as well as between simultaneously running workloads. Shared cloud infrastructure needs to protect the next customer from the previous customer’s data just as reliably as it separates their running applications.
📌 Register Now: The Validation Summit 26' The blueprint for readiness when attackers have AI 👇🏻