rustfs
crates.io6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rustfspage 1 of 1
- CVE-2025-68926CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.0.0-alpha.782025-12-30
RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, h…
- CVE-2025-69255MEDIUMCVSS 4.0EG 4.0✓ Fixed in 1.0.0-alpha.782026-01-07
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler…
- CVE-2026-22042HIGHCVSS 8.8EG 8.8✓ Fixed in 1.0.0-alpha.792026-01-08
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM pe…
- CVE-2026-22782HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.0-alpha.802026-01-16
RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers a…
- CVE-2026-39360MEDIUMCVSS 4.3EG 4.32026-04-07
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket c…
- CVE-2026-40937HIGHCVSS 8.3EG 8.32026-04-22
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication o…
Check whether rustfs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rustfs CVEs against the assets you own.
Start Free Scan →