PatchSiren

ceph CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ceph CVE published 2026-08-28

CVE-2025-30156

The CVE-2025-30156 vulnerability affects Ceph, an open-source distributed storage platform, specifically in its CephX authentication protocol. This protocol uses AES-128-CBC in an unauthenticated mode with a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. The vulnerability impacts Ceph users and administrators, as well [truncated]