Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
SeaweedFS bucket isolation isn’t isolation if X-Amz-Copy-Source can traverse paths. I break down the confused-deputy flaw, CVE-2026-55874, and the operator fixes.
https://ekofyi.com/blog/seaweedfs-x-amz-copy-source-path-traversal
Post summary
The post announces a path‑traversal vulnerability (CVE-2026-55874) in SeaweedFS triggered by X-Amz-Copy-Source and discusses operator‑level fixes to address it.
🚨 HIGH - SeaweedFS S3 gateway dot-dot path traversal in X-Amz-Copy-Source (CVE-2026-55874)
SeaweedFS S3 API gateway (CopyObject and UploadPartCopy) fails to properly reject dot-dot path segments in the X-Amz-Copy-Source header, enabling cross-bucket object access. The root cause is improper input validation leading to path traversal in server-side copy source parsing. An attacker with valid S3 credentials restricted to a single bucket can craft a CopyObject/UploadPartCopy request with ../ segments to reference and copy objects from other buckets through the gateway. Impact is unauthorized data access/data exfiltration across buckets, breaking tenant isolation and potentially exposing sensitive objects at scale.
👉 Affected: seaweedfs < 4.34 | Upgrade to 4.34
Post summary
The post discloses a CVE-2026-55874 path‑traversal flaw in SeaweedFS S3 gateway that allows cross‑bucket data exfiltration; upgrading to 4.34 fixes the issue.