Ceph
This hub aggregates every CVE we track for Ceph, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
2
Critical
18
High
0
In CISA KEV
Severity distribution
MEDIUM22HIGH18CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
1
1
0
0
0
1
0
0
0
0
0
0
0
0
4
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Ceph.
- CVE-2026-54330Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation8.1
- CVE-2026-50152Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users9.1
- CVE-2026-39944Ceph: CephX AES Authentication error8.8
- CVE-2025-30156Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery8.9
- CVE-2024-47866RGW DoS attack with empty HTTP header in S3 object copy7.5
- CVE-2024-48916Ceph is vulnerable to authentication bypass through RadosGW8.1
- CVE-2025-52555CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS6.5
- CVE-2023-43040IBM Spectrum Fusion HCI improper access control6.5
- CVE-2022-3854A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.6.5
- CVE-2022-3650A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.7.8
- CVE-2021-3979A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weake...6.5
- CVE-2022-0670A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "vol...9.1
- CVE-2020-27839A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to at...5.4
- CVE-2021-3531A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a d...5.3
- CVE-2021-3524A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The...6.5
Product normalization is registry-driven with AI assist and human review. How it works