9.1

CVE-2026-27607

RustFS's Missing Post Policy Validation leads to Arbitrary Object Write

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enables unauthorized file uploads exceeding size limits, uploads to arbitrary object keys, and content-type spoofing, potentially leading to storage exhaustion, unauthorized data access, and security bypasses. Version 1.0.0-alpha.83 fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rustfs ≫ Rustfs Version 1.0.0 Update alpha56 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha57 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha58 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha59 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha60 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha61 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha62 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha63 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha64 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha65 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha66 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha67 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha68 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha69 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha70 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha71 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha72 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha73 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha74 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha75 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha76 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha77 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha78 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha79 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha80 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha81 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha82 SwPlatform rust
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.176
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
security-advisories@github.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/rustfs/rustfs/security/advisories/GHSA-w5fh-f8xh-5x3p
Vendor Advisory