hacker-news · Crawled Sep 25, 2026
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Read original article ↗AI Summary
Cloudflare patched a vulnerability in its Containers and Sandboxes services that allowed a customer's container to read leftover disk data from previously deleted containers on the same server. The issue stemmed from thin-provisioned disks that were not properly wiped before reallocation, enabling data remnants—including SQLite databases, .env files, and browser profiles—to be recovered. The flaw was reported by researcher Oren Yomtov via Cloudflare's bug bounty program and was fixed by re-enabling block wiping and retiring all running container disks and caches. Cloudflare found no evidence of exploitation beyond authorized testing.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.