Cloudflare said in a blog post on October 5 that researcher Oren Yomtov of Accomplish reported a flaw on September 4, 2026. It affected Cloudflare Containers and Cloudflare Sandboxes, which are built on Containers. Cloudflare said a customer with a Workers Paid account could read leftover disk data once used by other customers' containers on the same host. The cause was a storage setting that skipped wiping new disk blocks. A small write then left the rest of a 64 KiB block holding the previous owner's data. The researchers reported leftover data on 18 of 24 placements and 20 of 22 nodes, across four continents. Cloudflare removed the setting, restarted the virtual machines, and cleared cached image copies. It finished on September 19.
Cloudflare said it has no evidence that customer data was compromised. It checked the past disk activity records it still had and found only the researchers and its own engineers running authorized tests. Cloudflare also said an attacker could not choose a victim. What leaked depended on where workloads ran and which freed blocks were reused. The post does not say how long the setting was in place or whose data sat in the blocks. The researchers said they securely deleted what they recovered.
Containers run many customers' workloads on shared hosts, so wiping freed disk space is part of the isolation customers rely on. Cloudflare said customers need to change nothing.