—
GO-2026-6329
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
Quick fix
GO-2026-6329 — github.com/seaweedfs/seaweedfs: upgrade to the fixed version with the command below.
go get github.com/seaweedfs/seaweedfs@v0.0.0-20260614205536-b13463880c1fDetails
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/seaweedfs/seaweedfs
Introduced in:
0.0.0-20260128085517-09bb90e8dc16Fixed in: 0.0.0-20260614205536-b13463880c1fFix
go get github.com/seaweedfs/seaweedfs@v0.0.0-20260614205536-b13463880c1fReferences
- https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-hgpf-8634-g44c[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-55873[ADVISORY]
- https://github.com/seaweedfs/seaweedfs/commit/b13463880c1fa62e255c058a9228b63cc95b4b36[FIX]
- https://github.com/seaweedfs/seaweedfs/pull/9961[FIX]
- https://github.com/seaweedfs/seaweedfs/releases/tag/4.34[WEB]