CVE-2026-54917

CRITICAL

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

Title source: cna
STIX 2.1

Description

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/pull/9687

Scores

CVSS v3 10.0
EPSS 0.0038
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
seaweedfs/seaweedfs < 4.30 (2 CPE variants)
Published Jun 25, 2026
Tracked Since Jun 26, 2026