SeaweedFS是SeaweedFS团队开源的一款分布式网络存储文件系统。 SeaweedFS 4.24之前版本存在授权问题漏洞,该漏洞源于未对SeaweedIdentityAccessManagement gRPC服务进行强制身份验证,当jwt.filer_signing.key未设置时,任何可访问filer gRPC端口的客户端均可调用CreateUser、CreateAccessKey、PutPolicy及相关IAM RPC,从而生成凭证并获得S3管理控制权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73080 | 9.3 CRITICAL | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeed |
| CVE-2026-72921 | 8.1 HIGH | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to s |
No comments yet