rustfs是RustFS开源的一个高性能对象存储系统。 RustFS 1.0.0-beta.2之前版本存在安全漏洞,该漏洞源于当RUSTFS_CORS_ALLOWED_ORIGINS未设置时,ConditionalCorsLayer会反射请求Origin值并设置宽松的跨域策略,可能导致浏览器在受害者具有凭据时发出跨域请求并读取响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45039 | 9.8 CRITICAL | RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer i |
| CVE-2026-45044 | RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated a | |
| CVE-2026-45042 | RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source | |
| CVE-2026-45040 | RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [D | |
| CVE-2026-45041 | RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery | |
| CVE-2026-47136 | RustFS: Unauthenticated RustFS console license endpoint exposes license metadata |
No comments yet