CVE-2026-55874
HIGHSeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
Title source: cnaDescription
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/pull/9929
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7f85ccd
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/releases/tag/4.34
Scores
CVSS v3
7.7
EPSS
0.0033
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
seaweedfs/seaweedfs
< 4.34
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026