Cloudflare Patches Container Vulnerability That Exposed Residual Disk Data Between Tenants
Cloudflare announced on Thursday that it has remedied a security weakness in its serverless container platform that could have allowed one paying customer to view leftover files from another customer's container on the same physical machine.
The flaw stemmed from the way the platform reclaimed disk space after a container finished its job. When a container released its storage, the underlying blocks were not overwritten, meaning a subsequent container could potentially read the data that remained on those blocks.
The issue was brought to light by independent security researchers who reported their findings to Cloudflare. In response, the company confirmed the vulnerability, initiated an internal investigation, and released a patch that introduces stricter data sanitization and isolation measures.
Technical analysis indicates that the containers share a common host operating system and rely on an ephemeral file system. While the system deletes file references when a container terminates, it does not automatically zero out the actual storage sectors. An attacker with access to a newly provisioned container could enumerate the raw disk and retrieve fragments of files left by a previous tenant.
Cloudflare says the vulnerability affected only its paid “Containers” service and that, to date, there is no evidence that any customer data was accessed maliciously. The company emphasized that the flaw was limited to residual disk data and did not expose runtime memory or network traffic.
Following the discovery, Cloudflare deployed a series of mitigations, including mandatory block wiping before reuse and enhanced isolation checks during container provisioning. The firm also pledged a broader audit of its serverless offerings to ensure similar oversights are addressed.
Security experts note that the incident underscores the importance of thorough data sanitization in multi‑tenant cloud environments, where resources are frequently recycled. Regulators and industry watchdogs may scrutinize such practices more closely as cloud services become increasingly integral to business operations.
Comments (0)
Be the first to comment.
Join the discussion