These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An authenticated S3 principal can overwrite an unauthorized object in SeaweedFS versions before 4.40 by exploiting a flawed PutObjectAcl request. This issue allows a user with permissions to a nested object key to modify a different object outside their access scope. The vulnerability arises from the handler writing the updated ACL entry to the bucket root instead of the object's parent directory, leading [truncated]
CVE-2026-77368 is a high-severity vulnerability in SeaweedFS, a distributed storage system for files and blobs. In version 4.39, a low-privilege tenant can hijack another tenant's TUS upload session, allowing unauthorized writes to filer paths that the tenant's token forbids. This occurs because the filer's TUS resumable-upload handler only checks JWT allowed_prefixes when a session is created, but not fo [truncated]
CVE-2026-77317 is a high-severity vulnerability in SeaweedFS, a distributed storage system. An authenticated low-privilege SFTP user can exploit this issue to access and overwrite files belonging to other tenants. The vulnerability is caused by a flawed path permission evaluation in the SFTP server, which allows users to access sibling paths with similar names. This issue has been fixed in version 4.40.
CVE-2026-77298 is a high-severity vulnerability in SeaweedFS, a distributed storage system. Versions 4.39 and earlier allow an external OIDC JWT sent directly in the Authorization header to map to an IAM role without enforcing that role's trust policy. This issue enables a federated user to assume a role they are not permitted to hold, potentially gaining unauthorized S3 access, including object read, wri [truncated]
CVE-2026-73080 is a critical vulnerability in SeaweedFS, a distributed storage system. The vulnerability exists in the VolumeServer.FetchAndWriteNeedle function, which allows unauthenticated requests to arbitrary hosts, including loopback, link-local, RFC 1918, and cloud metadata endpoints. This can lead to disclosure of instance metadata and IAM credentials, as well as access to otherwise unexposed inter [truncated]
CVE-2026-72921 is a high-severity vulnerability in SeaweedFS, a distributed storage system. The issue, fixed in version 4.24, allowed cross-tenant reads and writes due to improper authorization checks. This debrief provides an overview of the vulnerability, its impact, and recommended actions for defenders. Affected deployments should be verified for exposure, and defenders should prioritize upgrading to [truncated]
CVE-2026-72920 is a critical vulnerability in SeaweedFS, a distributed storage system. Prior to version 4.24, the system allows unauthenticated access to certain gRPC services, enabling attackers to create users, access keys, and policies, effectively gaining S3 administrative control. This issue is addressed in version 4.24. The vulnerability allows any client that can reach the filer gRPC port to invoke [truncated]
CVE-2026-54917 is a high-severity vulnerability in SeaweedFS, a distributed storage system for object storage (S3), file systems, and Iceberg tables. The vulnerability arises from the S3 API gateway and the Iceberg REST catalog gateway constructing their routers with mux.NewRouter().SkipClean(true), which disables path cleaning. This allows a .. segment inside the URL to survive routing, potentially leadi [truncated]