CVE-2026-54917
CRITICALSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
Title source: cnaDescription
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/pull/9687
Scores
CVSS v3
10.0
EPSS
0.0038
EPSS Percentile
31.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
seaweedfs/seaweedfs
< 4.30 (2 CPE variants)
Published
Jun 25, 2026
Tracked Since
Jun 26, 2026