<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:50:41.137987+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-seaweedfs-2026-55874</id>
    <title>BIT-seaweedfs-2026-55874 — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read</title>
    <updated>2026-10-02T20:50:41.143100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: seaweedfs</p>
<p>SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-seaweedfs-2026-55874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-334022</id>
    <title>EUVD-2026-334022</title>
    <updated>2026-10-02T20:50:41.143155+00:00</updated>
    <content>EUVD-2026-334022</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-334022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55874</id>
    <title>fkie_cve-2026-55874</title>
    <updated>2026-10-02T20:50:41.143172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-56wq-x3wv-3ff4</id>
    <title>GHSA-56wq-x3wv-3ff4 — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read</title>
    <updated>2026-10-02T20:50:41.143196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/seaweedfs/seaweedfs</p>
<p>### Summary
The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for emptiness, so a `..` segment in the copy source survived into the server-side filer path and resolved into a different bucket.</p>
<p>### Impact
A confused-deputy authorization bypass that breaks bucket isolation. IAM evaluates the caller's policy against the bucket named in the request URL (the destination the caller owns), while the copy reads its source from the traversed target bucket. An identity scoped to a single bucket (`Read` + `Write` on one bucket it controls) can therefore read any object in any bucket on the instance and land the result in its own bucket.</p>
<p>For example, a caller authorized only for `bucket-a` issues a `CopyObject` into `bucket-a` with copy source `bucket-a/../&lt;victim-bucket&gt;/&lt;key&gt;`; the gateway reads `&lt;victim-bucket&gt;/&lt;key&gt;` and writes it to the attacker-controlled destination, from which the caller reads it normally. `UploadPartCopy` (CopyObjectPartHandler) is affected by the same vector.</p>
<p>### Affected versions
All releases prior to 4.34. The 4.30 fix for CVE-2026-54917 hardened the request URL path but not the `X-Amz-Copy-Source` header.</p>
<p>### Patched version
4.34 and later.</p>
<p>### Remediation
Upgrade to 4.34 or later. The fix validates the copy-source bucket and object key with th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-56wq-x3wv-3ff4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68333</id>
    <title>RHSA-2026:68333 — Red Hat Security Advisory: Red Hat build of Cryostat security update</title>
    <updated>2026-10-02T20:50:41.143253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service v…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68333"/>
  </entry>
</feed>
