RustFS's RPC signature verification logs shared secret
Modified: 2/3/2026
package
pkg:crates.io/rustfs
RustFS's RPC signature verification logs shared secret
Modified: 2/3/2026
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
Modified: 2/3/2026
RustFS gRPC GetMetrics deserialization panic enables remote DoS
Modified: 2/3/2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
Modified: 2/3/2026
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
Modified: 5/5/2026
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
Modified: 4/10/2026
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
Modified: 5/5/2026
RustFS Path Traversal Vulnerability
Modified: 2/3/2026
RustFS Logs Sensitive Credentials in Plaintext
Modified: 2/22/2026
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
Modified: 2/25/2026
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
Modified: 2/3/2026
RustFS: Missing Post Policy Validation leads to Arbitrary Object Write
Modified: 2/25/2026
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
Modified: 2/3/2026