Cloudflare Fixes Cross-Tenant Data Exposure Flaw in Workers Containers and Sandboxes
Residual data recovery vulnerability affects customers on shared physical hardware

Key Takeaways
- Cloudflare fixed a cross-tenant data exposure vulnerability in Workers Containers and Sandboxes.
- The flaw could allow Paid account customers to recover residual data from other tenants on shared physical hardware.
- The issue is classified as a data residual risk, not a remote code execution vulnerability.
- No confirmed active exploitation has been reported.
- Customers are advised to verify configurations and update to the latest platform version.
Quick answers
- What happened?
- Cloudflare has addressed a cross-tenant vulnerability in its Workers Containers and Sandboxes service that could allow customers with a Paid account to recover residual data from other customers' containers on the same physical host. The issue was identified as a data residual risk rather than a remote code execution flaw. No confirmed active exploitation has been reported.
- Which products are affected?
- Workers, Containers, Sandboxes
- What should defenders do?
- Cloudflare has applied fixes to the Containers and Sandboxes service. Customers with Workers Paid accounts should verify their configurations and ensure they are running the latest platform version to benefit from the patch.
Cloudflare has fixed a vulnerability in its Containers and Sandboxes offering that could allow customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. The cross-tenant flaw pertains to data left behind after container teardown on shared infrastructure. The company stated that the issue relates to residual data exposure rather than remote code execution. Patches have been applied to the Containers and Sandboxes service. Customers with Workers Paid accounts are advised to verify their configurations and ensure they are running the latest platform version. No confirmed cases of active exploitation in the wild have been reported.
Security Details
The vulnerability resides in the Container and Sandboxes runtime on Cloudflare's Workers platform. It involves residual data exposure across tenant boundaries on shared physical hardware. The issue does not involve remote code execution but rather the potential recovery of leftover data from other customers' containers.
Affected products
Workers, Containers, Sandboxes
Mitigation
Cloudflare has applied fixes to the Containers and Sandboxes service. Customers with Workers Paid accounts should verify their configurations and ensure they are running the latest platform version to benefit from the patch.
Sources
BleepingComputer
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Sep 27, 2026 · 14:13
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



