📦 Rustfs

by Rustfs

🔍 What is Rustfs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-27822

CRITICAL CVSS 9.0 Feb 25, 2026

A stored cross-site scripting (XSS) vulnerability in RustFS Console allows attackers to inject malicious JavaScript that executes when administrators view the management console. This enables credenti...

CVE-2026-22043

CRITICAL CVSS 9.8 Jan 8, 2026

A privilege escalation vulnerability in RustFS IAM allows restricted service accounts or STS credentials to self-issue unrestricted service accounts with full parent privileges. This bypasses session ...

CVE-2025-68705

CRITICAL CVSS 9.8 Jan 7, 2026

CVE-2025-68705 is a path traversal vulnerability in RustFS's /rustfs/rpc/read_file_stream endpoint that allows attackers to read arbitrary files on the server filesystem. This affects RustFS versions ...

CVE-2025-68926

CRITICAL CVSS 9.8 Dec 30, 2025

This vulnerability allows attackers to bypass authentication in RustFS by using a hardcoded static token that is publicly exposed in the source code. Any attacker with network access to the gRPC port ...

CVE-2026-27607

HIGH CVSS 8.1 Feb 25, 2026

This vulnerability in RustFS allows attackers to bypass upload policy restrictions in presigned POST uploads, enabling unauthorized file uploads that exceed size limits, target arbitrary locations, an...

CVE-2026-24762

HIGH CVSS 7.5 Feb 3, 2026

RustFS versions alpha.13 through alpha.81 log sensitive AWS credentials (access keys, secret keys, session tokens) in plaintext at INFO level. This allows anyone with access to application logs to ste...

CVE-2026-21862

HIGH CVSS 7.5 Feb 3, 2026

This vulnerability allows attackers to bypass IP-based access controls in RustFS by spoofing their IP address using HTTP headers. Any client that can reach the RustFS service can impersonate allowed I...

CVE-2026-22782

HIGH CVSS 7.5 Jan 16, 2026

RustFS versions 1.0.0-alpha.1 through 1.0.0-alpha.79 log the shared HMAC secret when invalid RPC signatures are received. This exposes the secret to anyone with log access, enabling attackers to forge...

CVE-2026-22042

HIGH CVSS 8.8 Jan 8, 2026

This vulnerability in RustFS allows a principal with export-only IAM permissions to perform import operations, leading to unauthorized creation or modification of users, groups, policies, and service ...

CVE-2025-69255

MEDIUM CVSS 4.0 Jan 7, 2026

A malformed gRPC GetMetrics request can cause RustFS to panic and crash the handler thread, enabling remote denial of service attacks against the metrics endpoint. This affects RustFS versions 1.0.0-a...