CVE-2026-42882Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the percent-encoded request URI (r.URL.RequestURI()), while the bucket handler constructs S3 object keys from the decoded path (r.URL.Path). This mismatch, combined with the glob library being invoked without a path separator (causing * to match across / boundaries), allows unauthenticated attackers to write to, read from, or delete objects in protected S3 namespaces. Exploitation is possible via three techniques: (1) using * patterns that match across path separators to reach protected routes via path traversal (e.g., /open/foo/drafts/../restricted/), (2) using percent-encoded slashes (%2F) to collapse multiple path segments into a single token at the auth layer while the decoded form resolves to a protected namespace at the storage layer, and (3) using dot-dot segments (../) under ** prefix patterns, where the raw path matches an open route while Go's URL parser resolves the traversal to a protected path before the bucket handler runs. An unauthenticated attacker with network access can perform unauthorized PUT, GET, or DELETE operations on objects in authentication-protected S3 namespaces. This vulnerability is fixed in 5.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-23)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-05: 1Mentions · 2026-05-11: 1Mentions · 2026-06-23: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-23: 205-0505-1106-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-051
Patch1
2026-05-111
Disclosure1
2026-06-232
Disclosure2
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - S3-Proxy auth bypass (CVE-2026-42882) oxyno-zeta/s3-proxy mishandles URL path normalization (%2F vs /), leading to inconsistent routing and authorization checks - enabling access to protected objects. 👉 Affects versions < 0.0.0-20260424211602-1320e4abd46a 👉 Updating to the latest version is advised

    Post summary

    CVE‑2026‑42882 in s3‑proxy allows an authentication bypass due to path normalization mishandling; users are advised to upgrade to the latest version to mitigate the risk.

    00020124
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources CVE-2026-42882 Registry (CVSS 9.4, Published 2026-05-11) TL;DR CVE-2026-42882 is a CVSS 9.4 authentication bypass in the popular oxyno-zeta/s3-proxy project.

    Post summary

    The tweet announces the high-severity authentication bypass vulnerability CVE-2026-42882 in the oxyno-zeta/s3-proxy project, specifying its CVSS rating but offering no PoC, exploit, or patch details.

    1000064
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CVE-2026-42882 is a CVSS 9.4 authentication bypass in the popular oxyno-zeta/s3-proxy project. Attackers can bypass authentication middleware through URL path interpretation tricks, accessing protected S3 buckets without credentials. All versions before 5.0.0 are…

    Post summary

    The text announces CVE‑2026‑42882, an authentication bypass in oxyno‑zeta/s3‑proxy (CVSS 9.4) that lets attackers access protected S3 buckets via URL path tricks; all versions prior to 5.0.0 are vulnerable.

    1000064
    295 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42882 oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused… CVSS 9.4 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42882 #AWS #CyberSecurity #InfoSec

    Post summary

    Critical authentication bypass disclosed for oxyno‑zeta/s3‑proxy (CVE‑2026‑42882) with CVSS 9.4; no patch available yet.

    0000097
    90 followersView on X

Explore more