rustfs
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rustfs.
- CVE-2026-62378RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover9.0
- CVE-2026-55188RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials8.2
- CVE-2026-49991RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection8.6
- CVE-2026-55189RustFS: FTP frontend skips IAM authorization on object reads7.7
- CVE-2026-55838RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics4.3
- CVE-2026-45039RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation9.8
- CVE-2026-40937RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks8.3
- CVE-2026-39360RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration4.3
- CVE-2026-27822Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover9.0
- CVE-2026-27607RustFS's Missing Post Policy Validation leads to Arbitrary Object Write8.1
- CVE-2026-24762RustFS Logs Sensitive Credentials in Plaintext7.5
- CVE-2026-21862RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers7.5
- CVE-2026-22782RustFS RPC signature verification logs shared secret7.5
- CVE-2026-22043RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting9.8
- CVE-2026-22042RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation8.8