Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cloudflare Secures Containers After Disk Data Exposure

Cloudflare Secures Containers After Disk Data Exposure

Posted on September 25, 2026 By CWS

A vulnerability in Cloudflare’s container infrastructure allowed unauthorized access to residual data from other customers’ containers on shared servers. This issue, identified by researchers and confirmed by Cloudflare on Thursday, has been rectified to prevent further unauthorized data access.

Details of the Flaw

The flaw involved leftover data from previously used disk space, not from active workloads, as clarified by Cloudflare. Attackers couldn’t choose whose data was accessed. Cloudflare swiftly addressed this flaw, ensuring that customers need no further action.

Cloudflare Containers, which host customer applications on shared servers, was affected. This includes Cloudflare Sandboxes, marketed as a secure environment for executing untrusted code, including AI-generated scripts.

Discovery and Reporting

The vulnerability was reported to Cloudflare on September 4 by Oren Yomtov from Accomplish, a security firm, through their bug bounty program. The issue originated from improper disk management using a Linux feature known as thin provisioning, which allocates storage in 64-kilobyte increments.

When containers were deleted, their storage blocks returned to a shared pool without being wiped, allowing subsequent containers to access leftover data. The researchers demonstrated this by writing a small block and reading back the entire block, revealing data from previous containers.

Resolution and Security Measures

Cloudflare’s remediation involved re-enabling the wiping function for newly allocated blocks, effectively stopping the data exposure method. Researchers confirmed on September 14 that their method was ineffective post-update.

Further action included retiring all running container disks and clearing server caches to eliminate any residual data exposure risks. This comprehensive cleanup was completed by September 19, followed by public disclosure of the issue.

Cloudflare investigated potential misuse of this vulnerability by others but found no evidence beyond authorized testing by the researchers and its engineering team. The duration of the exposure remains unspecified due to incomplete historical records.

Implications and Future Outlook

The researchers noted that similar disk management issues affected Cloudflare’s Browser Run product. This flaw is their sixth sandbox escape since July, following vulnerabilities found in various other platforms like OpenAI’s Codex and Docker.

Cloudflare’s prompt response underscores the importance of robust security practices and continuous monitoring in cloud environments. The steps taken to secure customer data highlight the company’s commitment to maintaining a trustworthy service.

The Hacker News Tags:AI code execution, bug bounty, cloud security, Cloudflare, Cloudflare Sandboxes, container security, cybersecurity news, data leak, data protection, disk data, flaw remediation, secure containers, server security, thin provisioning, Vulnerability

Post navigation

Previous Post: Bitget Hot Wallet Breach Exposes $351.6 Million
Next Post: Cloudflare Secures Containers Against Data Leak Vulnerability

Related Posts

AI Revolutionizes Cybersecurity: The Rise of Vibe Hacking AI Revolutionizes Cybersecurity: The Rise of Vibe Hacking The Hacker News
Navigating the Mythos Era with Network Detection and Response Navigating the Mythos Era with Network Detection and Response The Hacker News
Security Risks in Budget Android TV Boxes Exposed Security Risks in Budget Android TV Boxes Exposed The Hacker News
SonicWall Patches Two Critical Zero-Day Vulnerabilities SonicWall Patches Two Critical Zero-Day Vulnerabilities The Hacker News
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation The Hacker News
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Roundcube Vulnerability Targeted by Cyber Attackers
  • Critical WSO2 and Adobe Flaws Exploited, CISA Alerts
  • Cloudflare Secures Containers Against Data Leak Vulnerability
  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Roundcube Vulnerability Targeted by Cyber Attackers
  • Critical WSO2 and Adobe Flaws Exploited, CISA Alerts
  • Cloudflare Secures Containers Against Data Leak Vulnerability
  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark