<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:50:37 +0000</lastBuildDate>
    <item>
      <title>BIT-seaweedfs-2026-55874 — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read</title>
      <link>https://cve.radiocsirt.org/vuln/bit-seaweedfs-2026-55874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: seaweedfs&lt;/p&gt;
&lt;p&gt;SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: seaweedfs&lt;/p&gt;
&lt;p&gt;SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-seaweedfs-2026-55874</guid>
    </item>
    <item>
      <title>EUVD-2026-334022</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334022</link>
      <description>EUVD-2026-334022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334022</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55874</link>
      <description>&lt;p&gt;SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55874</guid>
    </item>
    <item>
      <title>GHSA-56wq-x3wv-3ff4 — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-56wq-x3wv-3ff4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/seaweedfs/seaweedfs&lt;/p&gt;
&lt;p&gt;### Summary
The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for emptiness, so a `..` segment in the copy source survived into the server-side filer path and resolved into a different bucket.&lt;/p&gt;
&lt;p&gt;### Impact
A confused-deputy authorization bypass that breaks bucket isolation. IAM evaluates the caller&amp;#39;s policy against the bucket named in the request URL (the destination the caller owns), while the copy reads its source from the traversed target bucket. An identity scoped to a single bucket (`Read` + `Write` on one bucket it controls) can therefore read any object in any bucket on the instance and land the result in its own bucket.&lt;/p&gt;
&lt;p&gt;For example, a caller authorized only for `bucket-a` issues a `CopyObject` into `bucket-a` with copy source `bucket-a/../&amp;lt;victim-bucket&amp;gt;/&amp;lt;key&amp;gt;`; the gateway reads `&amp;lt;victim-bucket&amp;gt;/&amp;lt;key&amp;gt;` and writes it to the attacker-controlled destination, from which the caller reads it normally. `UploadPartCopy` (CopyObjectPartHandler) is affected by the same vector.&lt;/p&gt;
&lt;p&gt;### Affected versions
All releases prior to 4.34. The 4.30 fix for CVE-2026-54917 hardened the request URL path but not the `X-Amz-Copy-Source` header.&lt;/p&gt;
&lt;p&gt;### Patched version
4.34 and later.&lt;/p&gt;
&lt;p&gt;### Remediation
Upgrade to 4.34 or later. The fix validates the copy-source bucket and object key with th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/seaweedfs/seaweedfs&lt;/p&gt;
&lt;p&gt;### Summary
The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for emptiness, so a `..` segment in the copy source survived into the server-side filer path and resolved into a different bucket.&lt;/p&gt;
&lt;p&gt;### Impact
A confused-deputy authorization bypass that breaks bucket isolation. IAM evaluates the caller&amp;#39;s policy against the bucket named in the request URL (the destination the caller owns), while the copy reads its source from the traversed target bucket. An identity scoped to a single bucket (`Read` + `Write` on one bucket it controls) can therefore read any object in any bucket on the instance and land the result in its own bucket.&lt;/p&gt;
&lt;p&gt;For example, a caller authorized only for `bucket-a` issues a `CopyObject` into `bucket-a` with copy source `bucket-a/../&amp;lt;victim-bucket&amp;gt;/&amp;lt;key&amp;gt;`; the gateway reads `&amp;lt;victim-bucket&amp;gt;/&amp;lt;key&amp;gt;` and writes it to the attacker-controlled destination, from which the caller reads it normally. `UploadPartCopy` (CopyObjectPartHandler) is affected by the same vector.&lt;/p&gt;
&lt;p&gt;### Affected versions
All releases prior to 4.34. The 4.30 fix for CVE-2026-54917 hardened the request URL path but not the `X-Amz-Copy-Source` header.&lt;/p&gt;
&lt;p&gt;### Patched version
4.34 and later.&lt;/p&gt;
&lt;p&gt;### Remediation
Upgrade to 4.34 or later. The fix validates the copy-source bucket and object key with th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-56wq-x3wv-3ff4</guid>
    </item>
    <item>
      <title>RHSA-2026:68333 — Red Hat Security Advisory: Red Hat build of Cryostat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:68333</link>
      <description>&lt;p&gt;vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:68333</guid>
    </item>
  </channel>
</rss>
