Medium severity4.3NVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
CVE-2026-55873
CVE-2026-55873
Description
SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/seaweedfs/seaweedfsGo | >= 0.0.0-20260128085517-09bb90e8dc16, < 0.0.0-20260614205536-b13463880c1f | 0.0.0-20260614205536-b13463880c1f |
Affected products
3- osv-coords2 versions
< 4.34.0+ 1 more
- (no CPE)range: < 4.34.0
- (no CPE)range: < 0.0.20260902T191204-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-hgpf-8634-g44cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55873ghsaADVISORY
- github.com/seaweedfs/seaweedfs/commit/b13463880c1fa62e255c058a9228b63cc95b4b36nvdWEB
- github.com/seaweedfs/seaweedfs/pull/9961nvdWEB
- github.com/seaweedfs/seaweedfs/releases/tag/4.34nvdWEB
- github.com/seaweedfs/seaweedfs/security/advisories/GHSA-hgpf-8634-g44cnvdWEB
News mentions
0No linked articles in our index yet.