Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

rustfs — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting rustfs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rustfs is a Rust-based filesystem designed for secure, high-performance storage operations. Its core use case involves providing a reliable file system implementation with memory safety guarantees. Historically, common vulnerabilities affecting similar Rust filesystem implementations include remote code execution flaws through malicious filesystem images, cross-site scripting vulnerabilities in web management interfaces, and privilege escalation through improper access control. Rustfs has demonstrated strong memory safety characteristics due to Rust's ownership model, though it has recorded 12 CVEs, primarily focusing on denial-of-service vulnerabilities and input validation issues in its API endpoints. No major security incidents have been publicly documented for this specific implementation.

Found 32 results / 33 Clear Filters
Top products by rustfs: rustfs console
CVE ID Title CVSS Severity Published
CVE-2026-73290 RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback — rustfs CWE-863 5.3 Medium 2026-08-12
CVE-2026-73289 RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions — rustfs CWE-863 8.1 High 2026-08-12
CVE-2026-73288 RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted — rustfs CWE-693 6.1 Medium 2026-08-12
CVE-2026-73287 RustFS: FTPS MKD bypasses IAM CreateBucket authorization — rustfs CWE-862 5.4 Medium 2026-08-12
CVE-2026-73286 RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions — rustfs CWE-863 8.1 High 2026-08-12
CVE-2026-73285 RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged — rustfs CWE-863 7.5 High 2026-08-12
CVE-2026-73284 RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts — rustfs CWE-269 8.8 High 2026-08-12
CVE-2026-73265 RustFS: Version-specific object reads authorize the non-version action — rustfs CWE-862 6.5 Medium 2026-08-12
CVE-2026-55188 RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials — rustfs CWE-200 8.2 High 2026-06-26
CVE-2026-49991 RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection — rustfs CWE-22 8.6 High 2026-06-26
CVE-2026-55189 RustFS: FTP frontend skips IAM authorization on object reads — rustfs CWE-862 7.7 High 2026-06-26
CVE-2026-55838 RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics — rustfs CWE-862 4.3 Medium 2026-06-26
CVE-2026-45043 RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root — rustfs CWE-269 - - 2026-05-29
CVE-2026-46685 RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console — rustfs CWE-306 - - 2026-05-28
CVE-2026-45039 RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation — rustfs CWE-798 9.8 Critical 2026-05-28
CVE-2026-45040 RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode] — rustfs CWE-312 - - 2026-05-28
CVE-2026-45041 RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery — rustfs CWE-321 - - 2026-05-28
CVE-2026-45042 RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source — rustfs CWE-863 - - 2026-05-28
CVE-2026-45044 RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers — rustfs CWE-306 - - 2026-05-28
CVE-2026-47136 RustFS: Unauthenticated RustFS console license endpoint exposes license metadata — rustfs CWE-200 - - 2026-05-28
CVE-2026-40937 RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks — rustfs CWE-862 8.3 High 2026-04-22
CVE-2026-39360 RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration — rustfs CWE-862 6.5AI Medium AI 2026-04-07
CVE-2026-27822 Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover — rustfs CWE-79 9.1 Critical 2026-02-25
CVE-2026-27607 RustFS's Missing Post Policy Validation leads to Arbitrary Object Write — rustfs CWE-20 8.1 High 2026-02-25
CVE-2026-24762 RustFS Logs Sensitive Credentials in Plaintext — rustfs CWE-532 6.5AI Medium AI 2026-02-03
CVE-2026-21862 RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers — rustfs CWE-290 9.1AI Critical AI 2026-02-03
CVE-2026-22782 RustFS RPC signature verification logs shared secret — rustfs CWE-532 7.5 - 2026-01-16
CVE-2026-22043 RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting — rustfs CWE-269 8.8 - 2026-01-08
CVE-2026-22042 RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation — rustfs CWE-285 8.8 - 2026-01-08
CVE-2025-69255 RustFS gRPC GetMetrics deserialization panic enables remote DoS — rustfs CWE-755 7.5 - 2026-01-07

This page lists every published CVE security advisory associated with rustfs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.