Executive brief
Ceph Object Gateway (RGW) is a distributed storage service compatible with AWS S3. The service fails to validate x-amz-* headers on digitally signed requests, allowing attackers with a valid presigned URL to inject additional unsigned headers and gain elevated permissions. This breaks a core security property of presigned URLs, which should limit access to specific operations and capabilities intended by the URL signer.
Technical details
The vulnerability is a signature validation bypass in RGW's SigV4 handler. The root cause is that RGW only validates headers listed in the X-Amz-SignedHeaders field but ignores any additional x-amz-* or host headers present in the request, even though AWS S3 requires all such headers to be included in the signature. An attacker holding a presigned PUT URL can attach arbitrary unsigned x-amz-* headers (e.g., x-amz-storage-class, x-amz-acl) that RGW will honor without signature verification. The vulnerability affects versions prior to 20.2.4 and 19.2.6 and requires the attacker to already possess a valid presigned URL, making it a privilege escalation attack. Patches are available in versions 20.2.4, 19.2.6, and later.
Affected products
- Ceph Ceph prior to 20.2.4 and 19.2.6
Timeline
- 2026-08-28: disclosed
- 2026-08-17: patched: Fix merged in Ceph development branches