The Google Cloud Security Team has released a high-priority security advisory disclosing CVE-2026-45129 (CVSS 8.4), an information disclosure and identity token routing defect within Google Cloud Run serverless container execution infrastructure. The vulnerability allowed transient bearer tokens intended for one customer workload to leak into concurrent container requests under high-load multiplexing conditions.
Root Cause: Metadata Proxy Connection Multiplexing (CWE-200 / CWE-444)
Cloud Run containers interact with Google Cloud APIs by fetching ephemeral OAuth2 tokens from the local Compute Engine metadata server via http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token. To minimize latency and manage system throughput, the local gVisor sandbox daemon routes metadata queries through an internal connection multiplexer.
Security researchers discovered that under heavy concurrent HTTP keep-alive traffic, the proxy's internal connection pool failed to cleanly flush pipeline buffers when an upstream socket reset occurred. This created a race condition where the HTTP response containing an IAM service account token was returned to the subsequent connection in the reuse queue:
// Flawed connection reuse handler in metadata proxy daemon
func (p *MetadataProxy) handleRequest(req *http.Request) (*http.Response, error) {
conn := p.connPool.Get() // Reused TCP connection without verifying clean buffer drain
resp, err := conn.RoundTrip(req)
if err != nil {
p.connPool.Put(conn) // Leaked unread response bytes into next caller context
return nil, err
}
return resp, nil
}
Security Impact and Blast Radius
If an attacker had established an unprivileged foothold inside a co-hosted container instance on the same underlying hypervisor node, continuous concurrent polling of the metadata server could yield identity tokens assigned to different Cloud Run services, granting access to Cloud Storage buckets, BigQuery datasets, or Pub/Sub topics.
Remediation and Google Cloud Action
- Cloud Run Managed Service: Google rolled out a hotfix across all global regions that enforces strict per-container socket segregation and eliminates connection pooling for metadata authentication endpoints. No customer restart or configuration change is required.
- Anthos & Cloud Run on GKE: Administrators operating hybrid Anthos clusters must upgrade to Anthos GKE version 1.28.6-gke.12 or later to ingest the updated metadata agent daemon.
- Least Privilege IAM Auditing: Security teams are advised to review Cloud Run service accounts, ensuring they are not provisioned with broad Project Editor or Owner permissions.



