Futureweb

Distributed Cloud

What the Containers disclosure says was left on the host

Cloudflare says a Containers customer could read leftover disk data from another customer on the same host. The company says cleanup finished September 19.

The short version

Leftover disk data from another customer's earlier container on the same host. Cloudflare says the customer could not choose the victim, and that cleanup finished on September 19.

What happened

On September 24, 2026, Cloudflare posted that a storage flaw in Containers could let one customer read leftover disk data from another customer's earlier use of the same host. The post says Oren Yomtov of Accomplish reported it on September 4 through the company's bug bounty program, and that Sandboxes, which sit on Containers, were in scope. Customers, the post says, cannot choose the host. The technique could not target a particular customer, workload, host, or data, and leftover data was not guaranteed to be there. Cloudflare says the fleet is fixed, that no customer setting has to change, and that it found no evidence customer data was compromised. InfoQ wrote the item up on October 5. BleepingComputer reported the same disclosure. The page filing the post is Futureweb.

Who shared the host

The dependency in the post is the host the customer did not choose. Containers, Cloudflare writes, run on multi-tenant infrastructure and are assigned to eligible servers. Leftover data from storage a previous container had used on that host could be read by a later container belonging to a Workers Paid account. Cloudflare says an attacker could not select a victim and could not reach a disk that was still attached to someone else. The impact the company names is disclosure of filesystem metadata, directory structures, database pages, and application data. This page stops at that impact. It does not repeat the steps the researchers used to demonstrate it. A reader who wants the advisory shape, without those steps, is on Security.

What Cloudflare says it changed

Cloudflare says the first change stopped the reported technique, and that the researchers confirmed their demonstration no longer worked. The post also says that change did not wipe data already mapped into disks and cached image snapshots created before the fix. The company says it then retired running container disks, drained hosts, restarted the virtual machines, and cleared those cached snapshots. The timeline in the post runs from the September 4 report, through a same-day start of the rollout, a September 7 completion of that rollout, a September 14 note from the researchers that the demonstration had stopped, and a September 19 completion of the snapshot cleanup. Those dates are the company's.

Why it matters on this desk

This desk files where a workload sits, and who else sits on that machine. The Containers post is a placement fact. The customer did not choose the host, the host's storage had served other customers, and leftover bytes from that earlier use were the thing a later customer could read. Cloudflare says historical disk telemetry showed the reported activity only from the researchers and from Cloudflare engineers doing authorized checks. BleepingComputer and InfoQ both rest on that post. Neither outlet is a second forensic report with its own disk images. The desk that files a copy you can name without a region is Distributed Cloud.

What the placement does not share

A workload that never entered that shared host was outside the storage pool the post describes. Placement on machines the holder runs is the mechanism that answers that dependency, and it is the placement MATA.

What a reader can check

The check is Cloudflare's September 24 post. Does it name Containers and Sandboxes? Yes. Does it say customers pick the host? It says they cannot. Does it say a particular victim could be chosen? It says the technique could not. Does it give a customer setting to toggle? It says no customer change is required. Does it claim a public CVE number? The post does not. InfoQ's October 5 item and BleepingComputer's report track the same post. What a holder can still see in a record that is not this host is the privacy desk, Privacy.

What to watch next

The page changes if Cloudflare assigns a CVE, if a customer reports data that matches this disclosure, or if the company revises the no-evidence sentence. The September 19 cleanup date is the company's last completed step in the timeline it published. A later post that says leftover snapshots remain would replace that date. Until then the record is the September 24 account, and the October 5 coverage is a restatement of it. The content address of a copy, which does not depend on this host, is what a content address is.

What would change the record

A customer notice that names affected accounts, a CVE entry, or a revision of the telemetry claim would change the sentences above. A forum thread that repeats the impact without the post does not. Cloudflare says the researchers' materials submitted to the company contained no third-party filenames, credentials, or recovered content values, and that the researchers confirmed deletion of data they held. That is the company's account of the report, not a list of victims.

What stays a placement fact

What stays specific is the host the customer did not choose, the leftover data from an earlier container on that host, and the company's statement that the fleet cleanup finished on September 19 with no evidence of malicious use. A certificate application and a model release are not this disclosure. The brief stops at the impact the post names.

Sources

The reports this brief is filing. Futureweb did not republish them.

  1. Cloudflare, Containers disclosure (September 24, 2026)
  2. BleepingComputer, Cloudflare Containers fix
  3. InfoQ, Cloudflare Containers exposure

Questions

Which Cloudflare products did the September Containers disclosure cover?

Cloudflare Containers, and Cloudflare Sandboxes, which the post says are built on Containers. Customers could not choose the underlying host.

Who reported the Containers storage issue, and on what date?

Oren Yomtov of Accomplish, through Cloudflare's bug bounty program, on September 4, 2026. Cloudflare posted the account on September 24.

Could a Containers customer choose whose leftover data to read?

Cloudflare says no. The report could not target a particular customer, workload, host, or data, and leftover data was not guaranteed to be present.

Do Cloudflare Containers customers have a setting to change?

Cloudflare says no customer configuration change is required. The company says the fleet fix and the later cleanup are already done.

When does Cloudflare say the Containers cleanup finished?

September 19, 2026, for cleanup of cached snapshots from before the fix. Cloudflare says it found no evidence of malicious use.