High severity7.7OSV Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
CVE-2026-55874
CVE-2026-55874
Description
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-56wq-x3wv-3ff4ghsaADVISORY
- github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7f85ccdnvd
- github.com/seaweedfs/seaweedfs/pull/9929nvd
- github.com/seaweedfs/seaweedfs/releases/tag/4.34nvd
- github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4nvd
- nvd.nist.gov/vuln/detail/CVE-2026-55874ghsa
News mentions
0No linked articles in our index yet.