Browse all 7 CVE security advisories affecting ceph. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54330 | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation — ceph CWE-347 | 8.1 | High | 2026-08-27 |
| CVE-2026-50152 | Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users — ceph CWE-285 | 9.1 | Critical | 2026-08-27 |
| CVE-2026-39944 | Ceph: CephX AES Authentication error — ceph CWE-327 | 8.8 | High | 2026-08-27 |
| CVE-2025-30156 | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery — ceph CWE-327 | 8.9 | High | 2026-08-27 |
| CVE-2024-47866 | RGW DoS attack with empty HTTP header in S3 object copy — ceph CWE-20 | 7.5 | High | 2025-11-12 |
| CVE-2024-48916 | Ceph is vulnerable to authentication bypass through RadosGW — ceph CWE-345 | 8.1 | High | 2025-07-30 |
| CVE-2025-52555 | CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS — ceph CWE-269 | 6.5 | Medium | 2025-06-26 |
This page lists every published CVE security advisory associated with ceph. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.