What changed
On September 24, 2026 Cloudflare disclosed a vulnerability reported by Oren Yomtov of Accomplish on September 4. Cloudflare Containers used Linux dm-thin pools with skip_block_zeroing enabled. A new container could write 4 KiB into a newly allocated 64 KiB block and then read the remaining 60 KiB, which could still contain bytes from a previous tenant. Cloudflare says Sandboxes, which is built on Containers, was affected. The fleet was fixed and old mapped disks and cached image snapshots were retired by September 19.
Why it matters
The failure sits below the application sandbox boundary. A workload could be correctly isolated by Firecracker yet still receive storage containing another tenant's residual bytes. That matters especially for platforms running untrusted or AI-generated code: filesystem isolation, ephemeral disks and VM boundaries do not guarantee confidentiality if the underlying allocator reuses blocks without sanitising them.
A 4 KiB write could expose 60 KiB of old tenant data
The affected pools used 64 KiB dm-thin blocks and skip_block_zeroing. Researchers wrote one aligned 4 KiB block into unused filesystem regions, triggering allocation of a recycled physical block. Their subsequent raw-device read could expose the untouched 60 KiB remainder.
The researchers found real foreign filesystem material
Across production placements, Accomplish reported residual material on 18 of 24 placements and 20 of 22 underlying nodes across four continents. Cloudflare says recovered block types included directory structures, database pages and structurally complete SQLite databases. The researchers used ext4 checksums to distinguish foreign blocks from their own test filesystem.
Turning zeroing back on was only the first fix
Cloudflare removed skip_block_zeroing, but already mapped blocks and cached OCI image-layer snapshots could still contain pre-mitigation bytes. The company therefore retired running container disks, drained and restarted hosts and cleared image caches, completing cleanup on September 19.
Cloudflare found no evidence of malicious exploitation
Cloudflare built detection signatures from the proof of concept and searched the historical disk-I/O telemetry it retained. It says the only matching activity was authorized researcher and internal validation traffic. The disclosed telemetry window is not a guarantee that the flaw was never exploited outside the retained records.