Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

rustfs — Vulnerabilities & Security Advisories 32

All 32 CVE vulnerabilities found in rustfs, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities affecting rustfs, a file system implementation written in Rust. It aggregates reported security issues, configuration errors, and logic flaws identified across various versions of the software, providing a comprehensive view of its security posture over time. The collection spans from initial public releases to the most recent updates, ensuring that historical data remains accessible for forensic analysis and compliance auditing. Visitors can use this resource to track vendor advisories as they are published, gaining insight into how quickly the development team responds to critical findings. Additionally, users can understand specific weakness classes by examining recurring patterns in the reported bugs, which helps in assessing the overall robustness of the codebase against known attack vectors. By looking up rustfs's vulnerability history, developers and security professionals can make informed decisions about upgrade paths, patch prioritization, and risk mitigation strategies. This aggregation serves as a centralized reference point for understanding the lifecycle of security issues within the project, facilitating better communication between maintainers and the broader security community. Whether you are conducting a penetration test, performing a vulnerability scan, or simply reviewing the software's track record, this page provides the necessary context to evaluate potential risks accurately. The data is organized to support both high-level trend analysis and deep-dive technical investigations, ensuring that stakeholders at all levels can derive actionable intelligence from the available information.

Vendor: rustfs

CVE ID Title CVSS Severity Published
CVE-2026-73290 RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback CWE-863 5.3 Medium 2026-08-12
CVE-2026-73289 RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions CWE-863 8.1 High 2026-08-12
CVE-2026-73288 RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted CWE-693 6.1 Medium 2026-08-12
CVE-2026-73287 RustFS: FTPS MKD bypasses IAM CreateBucket authorization CWE-862 5.4 Medium 2026-08-12
CVE-2026-73286 RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions CWE-863 8.1 High 2026-08-12
CVE-2026-73285 RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged CWE-863 7.5 High 2026-08-12
CVE-2026-73284 RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts CWE-269 8.8 High 2026-08-12
CVE-2026-73265 RustFS: Version-specific object reads authorize the non-version action CWE-862 6.5 Medium 2026-08-12
CVE-2026-55188 RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials CWE-200 8.2 High 2026-06-26
CVE-2026-49991 RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection CWE-22 8.6 High 2026-06-26
CVE-2026-55189 RustFS: FTP frontend skips IAM authorization on object reads CWE-862 7.7 High 2026-06-26
CVE-2026-55838 RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics CWE-862 4.3 Medium 2026-06-26
CVE-2026-45043 RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root CWE-269 - - 2026-05-29
CVE-2026-46685 RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console CWE-306 - - 2026-05-28
CVE-2026-45039 RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation CWE-798 9.8 Critical 2026-05-28
CVE-2026-45040 RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode] CWE-312 - - 2026-05-28
CVE-2026-45041 RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery CWE-321 - - 2026-05-28
CVE-2026-45042 RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source CWE-863 - - 2026-05-28
CVE-2026-45044 RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers CWE-306 - - 2026-05-28
CVE-2026-47136 RustFS: Unauthenticated RustFS console license endpoint exposes license metadata CWE-200 - - 2026-05-28
CVE-2026-40937 RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks CWE-862 8.3 High 2026-04-22
CVE-2026-39360 RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration CWE-862 6.5AI Medium AI 2026-04-07
CVE-2026-27822 Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover CWE-79 9.1 Critical 2026-02-25
CVE-2026-27607 RustFS's Missing Post Policy Validation leads to Arbitrary Object Write CWE-20 8.1 High 2026-02-25
CVE-2026-24762 RustFS Logs Sensitive Credentials in Plaintext CWE-532 6.5AI Medium AI 2026-02-03
CVE-2026-21862 RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers CWE-290 9.1AI Critical AI 2026-02-03
CVE-2026-22782 RustFS RPC signature verification logs shared secret CWE-532 7.5 - 2026-01-16
CVE-2026-22043 RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting CWE-269 8.8 - 2026-01-08
CVE-2026-22042 RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation CWE-285 8.8 - 2026-01-08
CVE-2025-69255 RustFS gRPC GetMetrics deserialization panic enables remote DoS CWE-755 7.5 - 2026-01-07

All 32 known CVE vulnerabilities affecting rustfs with full Chinese analysis, references, and POCs where available.