Vulnerabilities in seaweedfs
12 resultsVexday analysis
SeaweedFS apresenta 5 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e ativo do fornecedor. Nenhuma está atualmente sob ataque explorado em campo (KEV) e não há críticas por CVSS, mas a fraqueza dominante é path traversal (CWE-22), que facilita acesso não autorizado a arquivos. O volume concentrado em janela curta sugere descobertas recentes que merecem avaliação rápida de aplicabilidade ao ambiente.
CVE-2026-54917HIGHSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessEPSS 1.6%CVE-2026-58372HIGHSeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body KeysEPSS 1.1%CVE-2026-72920CRITICALSeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlEPSS 0.8%CVE-2026-55874HIGHSeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readEPSS 0.6%CVE-2026-73080CRITICALSeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedleEPSS 0.5%CVE-2026-72921HIGHSeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsEPSS 0.4%CVE-2026-77298HIGHSeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policyEPSS 0.4%CVE-2026-77368HIGHSeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden PathsEPSS 0.4%CVE-2026-77611HIGHSeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a different object with the same basenameEPSS 0.4%CVE-2026-77317HIGHSeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwriteEPSS 0.4%CVE-2026-55873MEDIUMSeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table bucketsEPSS 0.3%CVE-2026-58371LOWSeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback ParameterEPSS 0.3%