Third party sites where the Google account was used for authorization, could have transmittted data through Cloudflare. (Think "Log in with Google" button on millions of sites.)
Fear might be shared email/passwords since thats really common.
What's the fear? Aren't all passwords encrypted on the server side?
But if an in-transit plaintext password is leaked by CloudFlare, server-side encryption is irrelevant.
(... that said, it's not like revoking sessions would impede a password-holding adversary...)