← Back

CVE-2026-27607

nvd nist
Published: Feb 25, 2026Modified: Feb 25, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enables unauthorized file uploads exceeding size limits, uploads to arbitrary object keys, and content-type spoofing, potentially leading to storage exhaustion, unauthorized data access, and security bypasses. Version 1.0.0-alpha.83 fixes the issue.

Affected (27)

Products: Rustfs: Rustfs
1 product
Rustfs
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Rustfs
Version 1.0.0 alpha56
Version 1.0.0 alpha57
Version 1.0.0 alpha58
Version 1.0.0 alpha59
Version 1.0.0 alpha60
Version 1.0.0 alpha61
Version 1.0.0 alpha62
Version 1.0.0 alpha63
Version 1.0.0 alpha64
Version 1.0.0 alpha65
Version 1.0.0 alpha66
Version 1.0.0 alpha67
Version 1.0.0 alpha68
Version 1.0.0 alpha69
Version 1.0.0 alpha70
Version 1.0.0 alpha71
Version 1.0.0 alpha72
Version 1.0.0 alpha73
Version 1.0.0 alpha74
Version 1.0.0 alpha75
Version 1.0.0 alpha76
Version 1.0.0 alpha77
Version 1.0.0 alpha78
Version 1.0.0 alpha79
Version 1.0.0 alpha80
Version 1.0.0 alpha81
Version 1.0.0 alpha82

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.