Executive brief
s3-proxy is a service used to provide an HTTP interface to S3 storage buckets. Multiple vulnerabilities in how the service matches web addresses to security rules allow attackers to bypass authentication. This means an unauthorized user could read, upload, or delete sensitive files in protected storage areas, potentially leading to data theft or service disruption.
Technical details
s3-proxy is vulnerable to multiple authentication bypasses due to inconsistent path handling between its authentication middleware and bucket handler. First, the glob matcher failed to use a path separator, allowing '*' to match across slashes (e.g., '/open/*/data' matching '/open/foo/../protected/data'). Second, the auth middleware matched against encoded URIs while the bucket handler used decoded paths, allowing '%2F' to collapse segments and bypass single-segment wildcards. Third, the lack of dot-segment normalization allowed path traversal (e.g., '/open/../restricted/') to be authorized as an 'open' path but executed as a 'restricted' path. These issues allow unauthenticated GET, PUT, and DELETE operations on protected S3 keys. A patch is available in version 0.0.0-20260424211602-1320e4abd46a.
Affected products
- oxyno-zeta s3-proxy < 0.0.0-20260424211602-1320e4abd46a
Timeline
- 2026-04-24: patched: Fix version released via commit hash.
- 2026-04-24: advisory: GitHub Advisory published.
- 2026-05-05: disclosed: CVE-2026-42882 assigned.