Vulnerability Description
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7
- https://github.com/seaweedfs/seaweedfs/pull/9929
- https://github.com/seaweedfs/seaweedfs/releases/tag/4.34
- https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4
FAQ
What is CVE-2026-55874?
CVE-2026-55874 is a vulnerability with a CVSS score of 7.7 (HIGH). SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an au...
How severe is CVE-2026-55874?
CVE-2026-55874 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55874?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.