---
id: CVE-2026-55874
title: >-
  SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure
  via S3 API gateway path traversal (CVE-2026-55874)
summary: >-
  A flaw was found in SeaweedFS, a distributed storage system. The S3 API
  gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers,
  specifically failing to reject "dot-dot" path segments. This allows an
  authenticated user,…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Cryostat 4 on RHEL 9
affected:
  - cryostat_4_on_rhel 9
patched:
  - cryostat_4_on_rhel 9
published: '2026-07-08'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:24:18+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55874.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55874.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55874'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2498092'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55874'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55874'
  - url: >-
      https://github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7f85ccd
  - url: 'https://github.com/seaweedfs/seaweedfs/pull/9929'
  - url: 'https://github.com/seaweedfs/seaweedfs/releases/tag/4.34'
  - url: >-
      https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4
  - url: 'https://access.redhat.com/errata/RHSA-2026:68333'
  - url: 'https://github.com/advisories/GHSA-56wq-x3wv-3ff4'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
epss: 0.00606
epssPercentile: 0.47695
aliases:
  - GHSA-56wq-x3wv-3ff4
ecosystem: go
ingestedAt: '2026-08-28T22:26:18.957Z'
---

## Overview

A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.

## Vendor advisories

- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)

**SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-16.

Fixed:

- Cryostat 4 on RHEL 9

Not affected:

- Cryostat 4 on RHEL 9

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-55874)

Affected packages:

- `github.com/seaweedfs/seaweedfs < 0.0.0-20260612000715-b44cf51fe931`

Patched in:

- `github.com/seaweedfs/seaweedfs 0.0.0-20260612000715-b44cf51fe931`

Source: https://github.com/advisories/GHSA-56wq-x3wv-3ff4
