Unfortunately they can, either through the unencrypted hostname passed in SNI or in the cert returned by the server .
[1] https://developers.cloudflare.com/ssl/edge-certificates/ech/
[1] https://developers.cloudflare.com/ssl/edge-certificates/ech/