CVE-2026-55874Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-08-29: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-08-29: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-29: 107-0808-29
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-08-291
Patch1
Full discourse2 posts
  • ekofyi@ekofyi
    Patch

    SeaweedFS bucket isolation isn’t isolation if X-Amz-Copy-Source can traverse paths. I break down the confused-deputy flaw, CVE-2026-55874, and the operator fixes. https://ekofyi.com/blog/seaweedfs-x-amz-copy-source-path-traversal

    Post summary

    The post announces a path‑traversal vulnerability (CVE-2026-55874) in SeaweedFS triggered by X-Amz-Copy-Source and discusses operator‑level fixes to address it.

    1000080
    170 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - SeaweedFS S3 gateway dot-dot path traversal in X-Amz-Copy-Source (CVE-2026-55874) SeaweedFS S3 API gateway (CopyObject and UploadPartCopy) fails to properly reject dot-dot path segments in the X-Amz-Copy-Source header, enabling cross-bucket object access. The root cause is improper input validation leading to path traversal in server-side copy source parsing. An attacker with valid S3 credentials restricted to a single bucket can craft a CopyObject/UploadPartCopy request with ../ segments to reference and copy objects from other buckets through the gateway. Impact is unauthorized data access/data exfiltration across buckets, breaking tenant isolation and potentially exposing sensitive objects at scale. 👉 Affected: seaweedfs < 4.34 | Upgrade to 4.34

    Post summary

    The post discloses a CVE-2026-55874 path‑traversal flaw in SeaweedFS S3 gateway that allows cross‑bucket data exfiltration; upgrading to 4.34 fixes the issue.

    00000108
    246 followersView on X

Explore more