CVE Browser

Page 1 (more results available)

Vendor: Rustfs Remove filter Clear all
CVE-2026-73290 MEDIUM

RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback

CVSS 5.3 EPSS 0.42% Aug 12, 2026
CVE-2026-73289 HIGH

RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions

CVSS 8.1 EPSS 0.41% Aug 12, 2026
CVE-2026-73288 MEDIUM

RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted

CVSS 6.1 EPSS 0.39% Aug 12, 2026
CVE-2026-73287 MEDIUM

RustFS: FTPS MKD bypasses IAM CreateBucket authorization

CVSS 5.4 EPSS 0.37% Aug 12, 2026
CVE-2026-73286 HIGH

RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions

CVSS 8.1 EPSS 0.43% Aug 12, 2026
CVE-2026-73285 HIGH

RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged

CVSS 7.5 EPSS 0.46% Aug 12, 2026
CVE-2026-73284 HIGH

RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts

CVSS 8.8 EPSS 0.52% Aug 12, 2026
CVE-2026-73265 MEDIUM

RustFS: Version-specific object reads authorize the non-version action

CVSS 6.5 EPSS 0.41% Aug 12, 2026
CVE-2026-62378 CRITICAL

RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover

CVSS 9.0 EPSS 0.49% Jul 15, 2026
CVE-2026-55188 HIGH

RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials

CVSS 8.2 EPSS 0.30% Jun 26, 2026
CVE-2026-49991 HIGH

RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection

CVSS 8.6 EPSS 0.41% Jun 26, 2026
CVE-2026-55189 HIGH

RustFS: FTP frontend skips IAM authorization on object reads

CVSS 7.7 EPSS 0.34% Jun 26, 2026
CVE-2026-55838 MEDIUM

RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics

CVSS 4.3 EPSS 0.27% Jun 26, 2026
CVE-2026-45043 CRITICAL

RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root

CVSS 9.3 EPSS 0.35% May 29, 2026
CVE-2026-46685 MEDIUM

RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console

CVSS 6.0 EPSS 0.15% May 28, 2026
CVE-2026-45039 CRITICAL

RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation

CVSS 9.8 EPSS 0.48% May 28, 2026
CVE-2026-45040 MEDIUM

RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]

CVSS 5.3 EPSS 0.24% May 28, 2026
CVE-2026-45041 HIGH

RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery

CVSS 8.7 EPSS 0.41% May 28, 2026
CVE-2026-45042 HIGH

RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source

CVSS 7.1 EPSS 0.35% May 28, 2026
CVE-2026-45044 HIGH

RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers

CVSS 8.8 EPSS 0.54% May 28, 2026
CVE-2026-47136 MEDIUM

RustFS: Unauthenticated RustFS console license endpoint exposes license metadata

CVSS 6.9 EPSS 0.54% May 28, 2026
CVE-2026-40937 HIGH

RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks

CVSS 8.3 EPSS 0.49% Apr 22, 2026
CVE-2026-39360 MEDIUM

RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration

CVSS 5.3 EPSS 0.28% Apr 7, 2026
CVE-2026-27822 CRITICAL

Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover

CVSS 9.1 EPSS 0.37% Feb 25, 2026
CVE-2026-27607 CRITICAL

RustFS's Missing Post Policy Validation leads to Arbitrary Object Write

CVSS 9.1 EPSS 0.41% Feb 25, 2026

Showing 1 to 25 CVEs · page 1 (more available)