股价创353美元历史新高次日,Cloudflare披露跨租户沙箱数据泄露
一项存储设置,让付费客户得以读取其他租户残留在回收磁盘块上的凭据文件和数据库。Cloudflare称未发现漏洞被利用的迹象,客户无需采取任何行动;同一周,公司市值达到1250亿美元。
Vincent Jiang · 3 min read
无人清零的60 KiB
就在Cloudflare股价触及353.04美元历史高点的次日,该公司发布了一份漏洞披露,对象正是处于其AI卖点核心的沙箱产品12。问题由Accomplish的Oren Yomtov于9月4日通过HackerOne报告:只要持有Workers付费版账户,他就能恢复同一主机上其他客户的容器曾使用、后已释放的磁盘块1。
原因出在一项设置上。容器根磁盘采用Linux精简置备(thin provisioning)技术,以64 KiB为单位分块;共享存储池又启用了skip_block_zeroing(跳过块清零)选项,回收的磁盘块未经清零便分配给了下一个租户1。只要往这样的块里写入4 KiB数据,再按原始方式读回,其余60 KiB中仍是上一位占用者的字节1。
2700个不属于他们的目录inode
在他们做过统计的6次部署中,研究人员检验了5614个可测试的目录块,没有一个能追溯到自己的文件系统,还识别出2700个互不相同的外来目录inode1。就全部部署而言,在横跨四大洲的底层节点中,24个里有18个、22个里有20个出现了残留数据13。Cloudflare确认存在目录结构、数据库页和结构完整的SQLite数据库;研究人员的报告还补充了Chromium用户配置文件、.env文件和凭据文件,并称这些文件属于其他客户134。
无利用迹象、无需行动、窗口期不明
Cloudflare根据概念验证(PoC)构建了检测规则,在其留存的磁盘I/O遥测数据上运行,结果只看到研究人员和自家工程师的授权测试;该公司表示,客户无需采取任何行动1。但官方文章从未说明skip_block_zeroing最初何时上线,暴露窗口期因此无从判断3。
研究人员称,同一套磁盘设置也影响了Browser Run(前身为Browser Rendering),而Cloudflare的披露文章并未点名这款产品349。租户若在权衡是否轮换经其流转过的凭据,如今需要纳入考量的攻击面又多了一个;平台一方的回答是:遥测数据足以让这个问题有定论13。
撑起股价的正是这款产品
受影响的这条产品线,恰恰是市场愿意出高价追捧的。Cloudflare将Sandbox SDK作为“安全运行不可信代码”的解决方案来销售,并配有教程,演示如何在该平台上运行Claude Code、Codex、Cursor的Cloud Agents以及Devin5。
2026年第二季度,Cloudflare季度营收达到6.96亿美元,同比增长36%67。这轮在353.04美元见顶的上涨将市值推至1250亿美元,年内上涨78%,瑞银目标价350美元,TD Cowen目标价355美元2。而就在一周前,该股还在300美元附近交投,内在价值估算仅为189美元7。
季度营收三年间翻了一倍多
Data
| 营收 | |
|---|---|
| 2023年三季度 | $335.6M |
| 2023年四季度 | $362.47M |
| 2024年一季度 | $378.6M |
| 2024年二季度 | $401M |
| 2024年三季度 | $430.08M |
| 2024年四季度 | $459.95M |
| 2025年一季度 | $479.09M |
| 2025年二季度 | $512.32M |
| 2025年三季度 | $562.03M |
| 2025年四季度 | $614.51M |
| 2026年一季度 | $639.76M |
| 2026年二季度 | $696.06M |
第六次沙箱逃逸
据Accomplish统计,这是7月以来的第六次沙箱逃逸,此前五次分别出自Claude Cowork、Claude Code、Cursor的CLI、Docker和OpenAI的Codex3;其中Codex的两次逃逸于8月12日报告,并在八天内修复8。现有记录既无法把这串逃逸与估值倍数挂钩,也无法排除两者的关联。且看第六次逃逸能否带来第五次没能带来的改变。Cloudflare卖的是AI代码的安全屋,而这个月,安全屋的地板是回收来的。
How this brief was made
01Gathered & sourced324 channels · 1,647 articles▾
Agents swept 324 channels and ingested 1,647 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated9 claims · 27 data feeds▾
Every one of 9 load-bearing claims was checked against primary sources, with 27 live data feeds reconciling the figures and charts.
- 1Cloudflare Blog, How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers, 24 September 2026
- 2Finance Review Daily, Cloudflare Stock Surges to All-Time High as AI Demand Fuels Rally, 23 September 2026
- 3The Hacker News, Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data, 25 September 2026
- 4CyberPress, Cloudflare Sandbox Escape Flaw Exposes Other Customers' Files and Credentials, 25 September 2026
- 5Cloudflare Docs, Sandbox SDK: Build secure, isolated code execution environments, updated 13 August 2026
- 6Sharadar quarterly fundamentals, from Cloudflare's SEC filings, retrieved 26 September 2026
- 7ad-hoc-news, Resilient Cloudflare stock holds near $300 as AI push and guidance lift valuation debate, 1 September 2026
- 8BleepingComputer, Researchers escape OpenAI Codex sandbox to run commands on host, 20 September 2026
- 9Cloudflare Docs, Browser Run: Run headless Chrome on Cloudflare's global network, updated 11 August 2026
03Reviewed & edited2 human editors▾
2 editors read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



