CVE-2026-55874High· 7.7▾ TwilightA flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate X-Amz-Copy-Source headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.
SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-16.
Fixed:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333
Workarounds / mitigations:
Affected packages:
github.com/seaweedfs/seaweedfs < 0.0.0-20260612000715-b44cf51fe931Patched in:
github.com/seaweedfs/seaweedfs 0.0.0-20260612000715-b44cf51fe931Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package
CVE-2025-59682High· 8.8django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)
CVE-2025-6020High· 7.8A flaw was found in linux-pam