importantSYS.SOURCE: The Hacker News• 2026-09-25T10:19:22+05:30
Cloudflare Addresses Container Security Flaw Allowing Cross-Customer Disk Data Access
Cloudflare addressed a vulnerability in its Containers service that allowed one customer's container to access leftover disk data from another customer's deleted container via improperly wiped storage blocks. The flaw was fixed by re-enabling disk wiping and clearing caches, with no evidence of malicious exploitation found.
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company
*** END OF TRANSMISSION ***