github.com
https://github.com/rustfs/rustfs/commit/98d3619613722308498494d412797a52ea8ae64d CVE-2026-73288
MEDIUM
RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted
Record summary
CVE-2026-73288 has a selected CVSS score of 6.1 (medium).
Description
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as no lock configuration, allowing objects under COMPLIANCE retention to be deleted or expired. This issue is fixed in version 1.0.0-rc.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
rustfsBrowse rustfs / rustfs | CVE List | < 1.0.0-rc.1 | affected |
References
4github.com
https://github.com/rustfs/rustfs/pull/5648 github.com
https://github.com/rustfs/rustfs/releases/tag/1.0.0-rc.1 github.comConfirmation
https://github.com/rustfs/rustfs/security/advisories/GHSA-j548-9grx-fh4f