<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:02:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265175</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265175</link>
      <description>EUVD-2026-265175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265175</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22043</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22043</link>
      <description>&lt;p&gt;RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions. Version 1.0.0-alpha.79 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions. Version 1.0.0-alpha.79 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22043</guid>
    </item>
    <item>
      <title>GHSA-xgr5-qc6w-vcg9 — RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xgr5-qc6w-vcg9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rustfs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**akin to MinIO CVE-2025-62506**&lt;/p&gt;
&lt;p&gt;- Policy evaluation: `Policy::is_allowed` returns true when `deny_only=true` if no explicit Deny is hit, skipping all Allow checks (`crates/policy/src/policy/policy.rs:66-74`).
- Service account creation path sets `deny_only=true` when the target user equals the caller or its parent (`rustfs/src/admin/handlers/service_account.rs:114-127`).
- Service accounts are created without `session_policy` by default, so claims lack `SESSION_POLICY_NAME`; combined with `deny_only`, self-operations are allowed without Allow statements.
- Result: a limited service account/STS can create a new service account without policy and obtain the parent’s full rights (even root), bypassing original restrictions.&lt;/p&gt;
&lt;p&gt;Key code references:&lt;/p&gt;
&lt;p&gt;- `crates/policy/src/policy/policy.rs` (deny_only short-circuit)
- `rustfs/src/admin/handlers/service_account.rs:` (deny_only set for self/parent target)
- `crates/iam/src/sys.rs` (service account creation defaults, no session_policy)&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;Requires `awscli`, `awscurl`, `jq`, RustFS at `http://127.0.0.1:9000`, root AK/SK `rustfsadmin/rustfsadmin`. Run:&lt;/p&gt;
&lt;p&gt;```bash
#!/usr/bin/env bash
set -euo pipefail&lt;/p&gt;
&lt;p&gt;# ===================== Config ======…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rustfs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**akin to MinIO CVE-2025-62506**&lt;/p&gt;
&lt;p&gt;- Policy evaluation: `Policy::is_allowed` returns true when `deny_only=true` if no explicit Deny is hit, skipping all Allow checks (`crates/policy/src/policy/policy.rs:66-74`).
- Service account creation path sets `deny_only=true` when the target user equals the caller or its parent (`rustfs/src/admin/handlers/service_account.rs:114-127`).
- Service accounts are created without `session_policy` by default, so claims lack `SESSION_POLICY_NAME`; combined with `deny_only`, self-operations are allowed without Allow statements.
- Result: a limited service account/STS can create a new service account without policy and obtain the parent’s full rights (even root), bypassing original restrictions.&lt;/p&gt;
&lt;p&gt;Key code references:&lt;/p&gt;
&lt;p&gt;- `crates/policy/src/policy/policy.rs` (deny_only short-circuit)
- `rustfs/src/admin/handlers/service_account.rs:` (deny_only set for self/parent target)
- `crates/iam/src/sys.rs` (service account creation defaults, no session_policy)&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;Requires `awscli`, `awscurl`, `jq`, RustFS at `http://127.0.0.1:9000`, root AK/SK `rustfsadmin/rustfsadmin`. Run:&lt;/p&gt;
&lt;p&gt;```bash
#!/usr/bin/env bash
set -euo pipefail&lt;/p&gt;
&lt;p&gt;# ===================== Config ======…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xgr5-qc6w-vcg9</guid>
    </item>
  </channel>
</rss>
