Junglewise Threat Intelligence

CVE-2026-54330: Ceph Object Gateway SigV4 signature bypass via unsigned headers

CVE-2026-54330 · Severity: high · CVSS 8.1 · Published 2026-08-28

Technologies: Ceph. Vendors: Ceph.

Executive brief

Ceph Object Gateway (RGW) is a distributed storage service compatible with AWS S3. The service fails to validate x-amz-* headers on digitally signed requests, allowing attackers with a valid presigned URL to inject additional unsigned headers and gain elevated permissions. This breaks a core security property of presigned URLs, which should limit access to specific operations and capabilities intended by the URL signer.

Technical details

The vulnerability is a signature validation bypass in RGW's SigV4 handler. The root cause is that RGW only validates headers listed in the X-Amz-SignedHeaders field but ignores any additional x-amz-* or host headers present in the request, even though AWS S3 requires all such headers to be included in the signature. An attacker holding a presigned PUT URL can attach arbitrary unsigned x-amz-* headers (e.g., x-amz-storage-class, x-amz-acl) that RGW will honor without signature verification. The vulnerability affects versions prior to 20.2.4 and 19.2.6 and requires the attacker to already possess a valid presigned URL, making it a privilege escalation attack. Patches are available in versions 20.2.4, 19.2.6, and later.

Affected products

  • Ceph Ceph prior to 20.2.4 and 19.2.6

Timeline

  • 2026-08-28: disclosed
  • 2026-08-17: patched: Fix merged in Ceph development branches

References

Related threats