Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

seaweedfs — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting seaweedfs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates recorded vulnerabilities for the seaweedfs vendor and product, focusing on specific weakness types and security tags. It collects a curated set of security advisories and incident reports, covering the time range from initial release through recent patches. Readers can track the vendor’s published advisories, analyze the distribution of weakness classes, and review the complete vulnerability history for this distributed file system product.

Found 12 results / 12 Clear Filters
Top products by seaweedfs: seaweedfs
CVE ID Title CVSS Severity Published
CVE-2026-77611 SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a different object with the same basename — seaweedfs CWE-863 7.1 High 2026-08-26
CVE-2026-77317 SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite — seaweedfs CWE-863 8.1 High 2026-08-26
CVE-2026-77298 SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy — seaweedfs CWE-863 8.7 High 2026-08-26
CVE-2026-77368 SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden Paths — seaweedfs CWE-639 7.6 High 2026-08-26
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle — seaweedfs CWE-918 9.3 Critical 2026-08-11
CVE-2026-72921 SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths — seaweedfs CWE-863 8.1 High 2026-08-11
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control — seaweedfs CWE-306 9.8 Critical 2026-08-11
CVE-2026-55873 SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets — seaweedfs CWE-863 4.3 Medium 2026-07-08
CVE-2026-55874 SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read — seaweedfs CWE-22 7.7 High 2026-07-08
CVE-2026-58372 SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys — seaweedfs CWE-22 8.1 High 2026-06-30
CVE-2026-58371 SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback Parameter — seaweedfs CWE-79 3.1 Low 2026-06-30
CVE-2026-54917 SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access — seaweedfs CWE-22 - - 2026-06-25

This page lists every published CVE security advisory associated with seaweedfs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.