Cloudflare has disclosed and fixed a cross-tenant data exposure issue affecting its Containers and Sandboxes products. The flaw involved storage reuse: a newly provisioned workload could receive disk blocks that still contained residual data from a previous customer.
How the isolation failure occurred
Researchers at Accomplish demonstrated that discarded thin-provisioned storage was not reliably cleared before reuse. That created a path for one tenant to inspect fragments left by another. Cloudflare said the affected products were in beta and reported no evidence that the issue had been exploited maliciously.
The company disabled the relevant storage behavior, introduced sanitization controls and reviewed the platform after receiving the report. Cloudflare’s account and the researchers’ technical write-up agree on the core risk, although they describe some affected service details differently. The incident illustrates that workload isolation depends on storage lifecycle controls as well as compute and network boundaries.
Lessons for multi-tenant platforms
Operators should include block-device reuse, snapshot handling and deprovisioning in tenant-isolation tests. Encryption, secure erase procedures and monitoring for unexpected reads can add defense in depth, but each control must be verified against the actual storage architecture. Customers should also avoid treating beta isolation guarantees as equivalent to mature production assurance. Related coverage appears in SectechMedia’s cyber-physical security channel.

Leave a Reply