Back to all news
Cybersecurity 2 min read

Fiji: Cloudflare Fixes Cross‑Tenant Data Exposure in Containers – What Companies

A vulnerability that could let one customer read leftover disk data from another has been fully remediated

Cloudflare has patched a cross‑tenant data exposure flaw in its Containers product after external researchers discovered residual disk data could be accessed by other tenants. The fix is complete and no customer data loss has been reported.

What happened

External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. The flaw allowed one tenant’s container to read leftover data on the underlying storage that belonged to another tenant. Cloudflare has fully remediated the vulnerability, and it reports no evidence that customer data has been compromised.

Why it matters

Cross‑tenant data exposure undermines the core security promise of multi‑tenant cloud services: isolation. If a container can read leftover files from a previous user, sensitive information such as credentials, proprietary code, or personal data could be unintentionally disclosed. For businesses that rely on Cloudflare Containers for web‑applications, APIs, or edge computing, the risk is a potential breach of confidentiality and compliance violations.

What this means for Fiji businesses

For organisations in Fiji and the broader Pacific that use Cloudflare’s edge platform, the incident highlights two practical points:

  1. Isolation Assurance – Even leading providers can have edge‑case isolation bugs. Ongoing verification of security controls remains essential.
  2. Vendor Transparency – Cloudflare’s prompt public disclosure and remediation demonstrate a mature incident‑response process, which is a positive signal for customers evaluating provider reliability.
  3. Regulatory Context – Fiji’s Data Protection Act 2022 requires organisations to protect personal data against unauthorized access. A cross‑tenant leak could trigger reporting obligations if data were exposed.

What businesses should do now

  1. Confirm Patch Status – Verify that your Cloudflare Containers instances are running the latest version released after the remediation. Contact Cloudflare support or check the dashboard for the patch timestamp.
  2. Review Access Controls – Ensure that only authorized personnel can deploy and manage containers. Use role‑based access and MFA for Cloudflare accounts.
  3. Audit Data Residue – Implement a process to wipe or encrypt temporary storage after each workload, especially for workloads handling sensitive data.
  4. Monitor Logs – Enable detailed logging for container creation, deletion, and data access. Set alerts for anomalous read patterns that could indicate residual data access.
  5. Update Incident‑Response Plans – Incorporate a scenario for cross‑tenant data exposure, outlining steps for containment, investigation, and regulatory notification.
  6. Engage with Vendors – Ask cloud providers for evidence of isolation testing and for any post‑remediation security assessments they have performed.

By taking these steps, Fiji businesses can reinforce their security posture, maintain compliance, and continue to benefit from the performance advantages of edge‑based container services.

Independent evidence

Sources

3 sources

Aura Digital Fiji · Digital services

Need help applying this technology to your business?

Custom websites, ecommerce, business email, security, mobile apps and IT systems built for Fiji businesses.

Continue reading

Related intelligence

All news →