Published event
CloudInfrastructure
SecurityIncident
3 source(s)
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
Summary
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers On September 4, 2026, Oren Yomtov, a security researcher from Accomplish , responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program . Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised.
Why it matters
This SecurityIncident is relevant to the technology intelligence record because it involves Cloudflare, Meta. The source article should remain the factual reference for follow-up coverage.
Key facts
- On September 4, 2026, Oren Yomtov, a security researcher from Accomplish , responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program .
- Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised.
- This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped us validate the issue and respond quickly.
- Cloudflare Containers run workloads on multi-tenant infrastructure and automatically assign them to eligible servers; customers cannot select the underlying host.
- The researchers demonstrated that a customer with a Workers Paid account could recover residual disk blocks previously used by Containers on the same host.
- The technique could not target a particular customer, workload, host, or data, and residual data was not guaranteed to be present.
Entities in this story
Related events