CVEs we hold for Rustfs
Records whose assigning authority named Rustfs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73290RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallbackrustfs
CVE-2026-73289RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisionsrustfs
CVE-2026-73288RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained…rustfs
CVE-2026-73286RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy…rustfs
CVE-2026-73285RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged…rustfs
CVE-2026-73284RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accountsrustfs
CVE-2026-62378RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeoverrustfs console
CVE-2026-55838RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metricsrustfs
CVE-2026-55188RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsrustfs
CVE-2026-49991RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injectionrustfs
CVE-2026-47136RustFS: Unauthenticated RustFS console license endpoint exposes license metadatarustfs
CVE-2026-46685RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on consolerustfs
CVE-2026-45044RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlersrustfs
CVE-2026-45043RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Rootrustfs
CVE-2026-45042RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Sourcerustfs
CVE-2026-45041RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgeryrustfs
CVE-2026-45040RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]rustfs
CVE-2026-45039RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonationrustfs
CVE-2026-40937RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of…rustfs
CVE-2026-39360RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationrustfs
CVE-2026-27822Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeoverrustfs
CVE-2026-22043RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Mintingrustfs
CVE-2026-22042RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalationrustfs
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.