{"id":"CVE-2026-55874","title":"SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)","summary":"A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject \"dot-dot\" path segments. This allows an authenticated user,…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cvssSource":"vendor","cwe":"CWE-22","vendor":"Red Hat","product":"Cryostat 4 on RHEL 9","affected":["cryostat_4_on_rhel 9"],"patched":["cryostat_4_on_rhel 9"],"published":"2026-07-08","updated":"2026-09-16","sourceUpdated":"2026-09-16T17:24:18+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55874.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55874.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55874"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498092"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55874"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55874"},{"url":"https://github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7f85ccd"},{"url":"https://github.com/seaweedfs/seaweedfs/pull/9929"},{"url":"https://github.com/seaweedfs/seaweedfs/releases/tag/4.34"},{"url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4"},{"url":"https://access.redhat.com/errata/RHSA-2026:68333"},{"url":"https://github.com/advisories/GHSA-56wq-x3wv-3ff4"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00606,"epssPercentile":0.47663,"aliases":["GHSA-56wq-x3wv-3ff4"],"ecosystem":"go","ingestedAt":"2026-08-28T22:26:18.957Z","slug":"CVE-2026-55874","body":"## Overview\n\nA flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject \"dot-dot\" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.\n\n## Vendor advisories\n\n- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)\n\n**SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-16.\n\nFixed:\n\n- Cryostat 4 on RHEL 9\n\nNot affected:\n\n- Cryostat 4 on RHEL 9\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-55874)\n\nAffected packages:\n\n- `github.com/seaweedfs/seaweedfs < 0.0.0-20260612000715-b44cf51fe931`\n\nPatched in:\n\n- `github.com/seaweedfs/seaweedfs 0.0.0-20260612000715-b44cf51fe931`\n\nSource: https://github.com/advisories/GHSA-56wq-x3wv-3ff4","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}