Cloudflare Containers and Sandboxes shared-disk reuse security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Cloudflare fixed a shared-disk reuse flaw in Cloudflare Containers and Cloudflare Sandboxes that let one customer read leftover data from other tenants on shared servers. The weakness came from thin-provisioned blocks that were reused without being wiped, creating cross-customer confidentiality risk on container disks. Researchers reported the issue on September 4, Cloudflare said the proof of concept stopped working on September 14, and cleanup finished on September 19.
Related Happenings
Cloudflare Workers remote Spectre leakage security flaw
Vulnerability
H score32
First: 19.08.2026 22:02
Last: 19.08.2026 22:02
Sources 1
About this happening:
Researchers disclosed a remote Spectre weakness in Cloudflare Workers that leaked a JWT from a co-located Worker in production, exposing a cross-tenant memory-read ris...
Cloudflare Workers remote Spectre leakage security flaw
VulnerabilityAbout this happening: Researchers disclosed a remote Spectre weakness in Cloudflare Workers that leaked a JWT from a co-located Worker in production, exposing a cross-tenant memory-read ris...
Linux kernel XFS reflink local root flaw (CVE-2026-64600)
Vulnerability
H score83
First: 23.07.2026 11:04
Last: 23.07.2026 11:04
Sources 1
About this happening:
CVE-2026-64600 is a Linux kernel XFS reflink race condition, dubbed RefluXFS by Qualys TRU, that can let an unprivileged local user overwrite root-owned file...
Linux kernel XFS reflink local root flaw (CVE-2026-64600)
VulnerabilityAbout this happening: CVE-2026-64600 is a Linux kernel XFS reflink race condition, dubbed RefluXFS by Qualys TRU, that can let an unprivileged local user overwrite root-owned file...
Linux kernel GhostLock root privilege escalation (CVE-2026-43499)
Vulnerability
H score28
First: 08.07.2026 09:16
Last: 08.07.2026 09:16
Sources 1
About this happening:
Researchers disclosed GhostLock (CVE-2026-43499), a Linux kernel use-after-free that can let a logged-in local user gain full root control on unpatched systems. Th...
Linux kernel GhostLock root privilege escalation (CVE-2026-43499)
VulnerabilityAbout this happening: Researchers disclosed GhostLock (CVE-2026-43499), a Linux kernel use-after-free that can let a logged-in local user gain full root control on unpatched systems. Th...
Publicly exposed training and demo apps in cloud environments are being abused at scale
Trend
H score29
First: 11.02.2026 13:30
Last: 11.02.2026 13:30
Sources 1
About this happening:
Publicly exposed training and demo applications are showing up at scale in AWS, Azure, and GCP, turning lab systems into real cloud footholds. Researchers verified nearl...
Publicly exposed training and demo apps in cloud environments are being abused at scale
TrendAbout this happening: Publicly exposed training and demo applications are showing up at scale in AWS, Azure, and GCP, turning lab systems into real cloud footholds. Researchers verified nearl...
Ghostscript OpenSC and CGIF memory corruption flaws memory corruption flaw
Vulnerability
H score0
First: 06.02.2026 07:49
Last: 06.02.2026 07:49
Sources 1
About this happening:
Ghostscript, OpenSC, and CGIF were among the open-source libraries affected by a newly disclosed batch of more than 500 previously unknown high-severity flaws. The...
Ghostscript OpenSC and CGIF memory corruption flaws memory corruption flaw
VulnerabilityAbout this happening: Ghostscript, OpenSC, and CGIF were among the open-source libraries affected by a newly disclosed batch of more than 500 previously unknown high-severity flaws. The...
Timeline
-
25.09.2026 07:49 1 articles · 4h ago
Accomplish reports leftover-disk data exposure in Cloudflare Containers and Sandboxes
Initial DisclosureOren Yomtov of Accomplish reported through Cloudflare's bug bounty program that Cloudflare Containers and Cloudflare Sandboxes could expose leftover disk data from other customers' containers on shared servers when thin-provisioned blocks were reused without wiping.
Show sources
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data — thehackernews.com — 25.09.2026 07:49
-
25.09.2026 07:49 1 articles · 4h ago
Cloudflare re-enables wiping for reused blocks and stops the proof of concept
Mitigation Patch UpdateCloudflare turned wiping back on for newly handed-out thin-provisioned blocks, and the researchers confirmed on September 14 that their proof of concept no longer worked.
Show sources
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data — thehackernews.com — 25.09.2026 07:49
-
25.09.2026 07:49 1 articles · 4h ago
Cloudflare retires running container disks and clears cached image layers
Mitigation Patch UpdateCloudflare retired every running container disk, cleared the caches of prepared image layers, and drained and restarted servers during quiet hours to remove blocks that a new container could inherit and read.
Show sources
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data — thehackernews.com — 25.09.2026 07:49
-
25.09.2026 07:49 2 articles · 4h ago
Cloudflare says only authorized testing used the leftover-disk read method
Detection Ioc UpdateCloudflare disclosed the flaw five days after cleanup finished and said it built detection signatures from the researchers' proof of concept and its own copy of the attack, ran them against retained disk-activity records, found only the researchers' and its own engineers' authorized testing, and saw no evidence that this specific method was used by anyone else.
Show sources
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data — thehackernews.com — 25.09.2026 07:49
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data — thehackernews.com — 25.09.2026 07:49