Executive brief
RustFS, a distributed object storage system, contains a hard-coded private encryption key within its source code. This key is used to verify software licenses when the licensing feature is enabled. Because the key is publicly available in the source code and compiled binaries, any user can generate their own valid license tokens, effectively bypassing license enforcement and usage restrictions.
Technical details
RustFS prior to version 1.0.0-beta.2 includes a hard-coded 2048-bit RSA private key (TEST_PRIVATE_KEY) in 'crates/appauth/src/token.rs'. This key is used in production by the 'parse_license()' function to verify license tokens. The implementation incorrectly uses RSA PKCS#1 v1.5 decryption as a substitute for a digital signature scheme; because the private key is embedded in the source and binaries, any attacker can encrypt a crafted JSON payload to 'mint' a valid license. This bypasses the license-enforcement mechanism when the 'license' Cargo feature is enabled. The vulnerability is addressed in version 1.0.0-beta.2 by removing the embedded key and moving toward a proper signature-based verification model.
Affected products
- RustFS RustFS < 1.0.0-beta.2
Timeline
- 2026-05-09: advisory: GitHub Security Advisory published
- 2026-05-28: disclosed: CVE published to NVD
- 2026-05-28: patched: Fixed in version 1.0.0-beta.2