Cloudflare fixed Containers isolation flaw
Cloudflare fixed a Containers isolation flaw that could expose residual data between customers. UpGuard also found thousands of exposed Supabase databases.
Cloudflare fixed a Containers isolation flaw that could let residual data from one customer be recovered by another on the same underlying host. In parallel, UpGuard found thousands of Supabase databases with personal data exposed online, while Latin America and the Caribbean move ahead with rules to identify trusted providers in digital infrastructure.
Cloudflare fixed a customer-isolation flaw in Containers that could have allowed recovery of residual data from storage blocks previously used by other customers on the same underlying host. The company said the issue would have affected customers with a Workers Paid account, and the mitigation included removing skip_block_zeroing, re-enabling block zeroing, removing existing container disks, and clearing caches, according to a threat intelligence summary that placed the end of those actions on September 19, 2026.
What did Cloudflare's flaw expose?
The vulnerability could have left residual storage data accessible to other Containers customers. Cloudflare said the case may have let a customer with Workers Paid recover remnants of blocks previously used on the same underlying host.
An independent analysis attributed to Mallory AI said the problem appears to have originated in Linux dm-thin storage pools configured with skip_block_zeroing. According to that report, 64 KiB blocks could retain up to 60 KiB of residual data after a 4 KiB write.
Other technical coverage, including ISeC News, said tests were able to recover directory structures, database pages, and full SQLite databases from blocks used by other customers. That report added that the result did not imply access to live disks or allow a specific victim to be selected.
GBHackers also said the exposure could extend to Cloudflare Sandboxes, built on Containers, and mentioned potential artifacts that could be recovered, including .env files, Chromium profiles, and credential data.
What did Cloudflare do to mitigate it?
Cloudflare removed skip_block_zeroing, re-enabled block zeroing, and removed existing container disks. It also cleared caches, according to the HawkEye summary, which placed the completion of those measures on September 19, 2026.
Public confirmation of the fix came after specialized media reported the flaw. BleepingComputer said the company had patched a cross-tenant exposure vulnerability in Containers, while Cloudflare's official blog explained the scope in terms of residual data recoverable between customers.
What other findings came up in parallel?
UpGuard found 16,326 Supabase databases with publicly readable tables, according to the available coverage. Diario Bitcoin reported that the finding included personal information accessible from the internet, such as contact details, passwords, and tokens.
Taken together, the two cases again put pressure on cloud services and data platforms that run multiple customers on the same infrastructure. For companies in Latin America using those environments, exposure depends not only on their own configuration but also on the isolation their providers promise.
What is happening in the region with digital infrastructure providers?
The United States and 14 governments in Latin America and the Caribbean agreed to promote rules to identify trusted providers in digital infrastructure, according to Reuters. El Economista added that the regional initiative also targets telecommunications.
That regulatory move comes as cloud incidents and exposed databases continue to create room to reassess how the providers supporting critical services in the region are classified and overseen.
Sources
- Americas news pagereuters.com· ReutersUnverified URL
- Cloudflare Fixes Cross Tenant Data Exposure Flaw in Containersisec.news· ISeC News
- Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloadsgbhackers.com· GBHackers
- UpGuard detecta 16.000 bases de datos de Supabase con información personal expuestadiariobitcoin.com· Diario Bitcoin
- Cloudflare fixes Containers cross-tenant flaw exposing customer datableepingcomputer.com· BleepingComputer
- Cloudflare blogblog.cloudflare.com· Cloudflare
- América Latina impulsa reglas para proveedores de infraestructura digital y telecomeleconomista.com.mx· El Economista
- Cloudflare Fixes Cross-Tenant Residual Data Exposure in Containersmallory.ai· Mallory AI
- Weekly Threat Landscape Digest - Week 39hawk-eye.io· HawkEye



