Cloudflare disclosed a cross-tenant sandbox leak the day after its stock hit a record $353
One storage setting let a paying customer read other tenants' leftover credential files and databases off recycled disk blocks. Cloudflare says it found no exploitation and customers need do nothing; the same week, its market cap reached $125 billion.
Vincent Jiang · 3 min read
Sixty kilobytes nobody wiped
A day after Cloudflare stock touched an all-time high of $353.04, the company published a disclosure about the sandbox products at the center of its AI pitch 12. Oren Yomtov of Accomplish had reported the issue through HackerOne on 4 September: with a Workers Paid account, he could recover disk blocks that other customers' containers had used and surrendered on the same host 1.
The cause was one setting. Container root disks use Linux thin provisioning in 64 KiB blocks, and the shared pool ran with skip_block_zeroing, so a recycled block reached the next tenant unwiped 1. Write 4 KiB into such a block and read it back raw: the other 60 KiB still held the previous occupant's bytes 1.
2,700 directory inodes that were not theirs
In the six placements where they counted, the researchers examined 5,614 testable directory blocks, attributed zero to their own filesystem, and identified 2,700 distinct foreign directory inodes 1. Across every placement, residual material surfaced on 18 of 24 and on 20 of 22 underlying nodes, across four continents 13. Cloudflare confirms directory structures, database pages and structurally complete SQLite databases; the researchers' write-up adds Chromium profiles, .env files and credential files, and describes them as other customers' files 134.
No evidence, no action, no window
Cloudflare built detections from the proof of concept, ran them over the disk-I/O telemetry it retains, and saw only the researchers' and its own engineers' authorized testing; customers need do nothing, it says 1. The post never says when skip_block_zeroing first shipped, so the exposure window is unknown 3.
The researchers say the same disk setup affected Browser Run (formerly Browser Rendering), a product Cloudflare's post does not name 349. That is one more surface in scope for tenants weighing rotation of credentials that ran through it, against a platform whose answer is that its telemetry settles the question 13.
The product is the rally
The affected line is the one the market is paying up for. Cloudflare sells its Sandbox SDK as the way to "run untrusted code securely," with tutorials for running Claude Code, Codex, Cursor Cloud Agents and Devin on it 5.
Quarterly revenue reached $696M in Q2 2026, up 36% 67. The rally that peaked at $353.04 put the market cap at $125 billion, up 78% on the year, with UBS at a $350 target and TD Cowen at $355 2. A week earlier the shares traded near $300, an intrinsic-value estimate of $189 underneath them 7.
Quarterly revenue has more than doubled in three years
Data
| Revenue | |
|---|---|
| Q3 '23 | $335.6M |
| Q4 '23 | $362.47M |
| Q1 '24 | $378.6M |
| Q2 '24 | $401M |
| Q3 '24 | $430.08M |
| Q4 '24 | $459.95M |
| Q1 '25 | $479.09M |
| Q2 '25 | $512.32M |
| Q3 '25 | $562.03M |
| Q4 '25 | $614.51M |
| Q1 '26 | $639.76M |
| Q2 '26 | $696.06M |
Escape number six
Accomplish counts this as its sixth sandbox escape since July, after Claude Cowork, Claude Code, Cursor's CLI, Docker and OpenAI's Codex 3; the Codex pair was reported on 12 August and patched inside eight days 8. Nothing in the record ties the streak to the multiple, and nothing rules it out either. Watch whether escape number six changes anything the fifth did not. Cloudflare is selling the safe room for AI code, and this month the floor was recycled.
How this brief was made
01Gathered & sourced324 channels · 1,647 articles▾
Agents swept 324 channels and ingested 1,647 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated9 claims · 27 data feeds▾
Every one of 9 load-bearing claims was checked against primary sources, with 27 live data feeds reconciling the figures and charts.
- 1Cloudflare Blog, How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers, 24 September 2026
- 2Finance Review Daily, Cloudflare Stock Surges to All-Time High as AI Demand Fuels Rally, 23 September 2026
- 3The Hacker News, Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data, 25 September 2026
- 4CyberPress, Cloudflare Sandbox Escape Flaw Exposes Other Customers' Files and Credentials, 25 September 2026
- 5Cloudflare Docs, Sandbox SDK: Build secure, isolated code execution environments, updated 13 August 2026
- 6Sharadar quarterly fundamentals, from Cloudflare's SEC filings, retrieved 26 September 2026
- 7ad-hoc-news, Resilient Cloudflare stock holds near $300 as AI push and guidance lift valuation debate, 1 September 2026
- 8BleepingComputer, Researchers escape OpenAI Codex sandbox to run commands on host, 20 September 2026
- 9Cloudflare Docs, Browser Run: Run headless Chrome on Cloudflare's global network, updated 11 August 2026
03Reviewed & edited2 human editors▾
2 editors read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.


