Junglewise Threat Intelligence

CVE-2026-49991: RustFS path traversal in Snowball auto-extract feature

CVE-2026-49991 · Severity: high · CVSS 8.6 · Published 2026-06-26

Technologies: Rustfs.

Executive brief

RustFS is a distributed storage system used to manage large amounts of data across multiple users or 'tenants.' A security flaw in its data extraction feature allows a user to bypass security boundaries and write files into other users' private storage areas. This could lead to unauthorized data modification, malware injection, or the corruption of sensitive information belonging to other customers.

Technical details

A path traversal vulnerability exists in the RustFS Snowball auto-extract feature due to a chain of three flaws. First, the 'normalize_extract_entry_key' function fails to sanitize '../' sequences in tar entry keys. Second, IAM wildcard matching is performed against raw, uncleaned paths, allowing 'attacker-bucket/../victim-bucket' to match 'attacker-bucket/*'. Finally, the filesystem path resolution logic resolves parent directory references across bucket boundaries. An authenticated attacker with PutObject permissions on their own bucket can upload a malicious archive that, when extracted, writes arbitrary files into a victim's bucket. No patch is currently listed in the advisory.

Affected products

  • rustfs RustFS 1.0.0-beta.4

Timeline

  • 2026-06-01: advisory: GitHub advisory published
  • 2026-06-26: disclosed: NVD publication date

References