Technology · crates.io
rustfs (crates.io) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in rustfs (crates.io): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55838, was published on 26 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About rustfs (crates.io)
A Rust crate providing a filesystem abstraction layer.
Latest rustfs (crates.io) vulnerabilities
- CVE-2026-55838: RustFS missing authorization in metrics endpointmediumCVSS 4.3
- CVE-2026-55189: rustfs RustFS missing authorization in FTP frontend object readshighCVSS 7.7
- CVE-2026-55188: RustFS authorization bypass in ListRemoteTargetHandler replication APIhighCVSS 8.2
- CVE-2026-49991: RustFS path traversal in Snowball auto-extract featurehighCVSS 8.6
- CVE-2026-45043: RustFS privilege escalation in ImportIAM endpointinfoCVSS 9.3
- CVE-2026-47136: RustFS missing authentication in console license endpointinfoCVSS 6.9
- CVE-2026-46685: RustFS permissive CORS policy in S3 listenerinfoCVSS 6
- CVE-2026-45044: RustFS missing authentication in admin profiling endpointsinfoCVSS 8.8
- CVE-2026-45042: RustFS improper authorization in UploadPartCopy operationinfoCVSS 7.1
- CVE-2026-45041: RustFS hard-coded RSA private key in license verifierinfoCVSS 8.7
- CVE-2026-45040: RustFS sensitive information leakage in logsinfoCVSS 5.3
- CVE-2026-45039: RustFS hard-coded default HMAC secret in internode RPC layercriticalCVSS 9.8
- RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeovermediumCVSS 4
- CVE-2026-40937: RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhookshighCVSS 8.3EPSS 0.5%
- CVE-2026-39360: RustFS missing authorization in multipart UploadPartCopymediumCVSS 4.3EPSS 0.3%
- CVE-2026-27822: Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account TakeoverlowCVSS 3.1EPSS 0.4%
- CVE-2026-27607: RustFS: Missing Post Policy Validation leads to Arbitrary Object WritelowCVSS 3.1EPSS 0.4%
- CVE-2026-24762: RustFS Logs Sensitive Credentials in PlaintextmediumCVSS 4EPSS 0.3%
- CVE-2026-21862: RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headersmediumCVSS 4EPSS 0.2%
- CVE-2026-22782: RustFS's RPC signature verification logs shared secretmediumCVSS 4EPSS 0.5%
- CVE-2026-22043: RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingmediumCVSS 4EPSS 0.4%
- CVE-2026-22042: RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege EscalationmediumCVSS 4EPSS 0.4%
- CVE-2025-69255: RustFS gRPC GetMetrics deserialization panic enables remote DoSmediumCVSS 4EPSS 0.3%
- CVE-2025-68705: RustFS Path Traversal VulnerabilitymediumCVSS 4EPSS 7.4%
- CVE-2025-68926: RustFS has a gRPC Hardcoded Token Authentication BypasslowCVSS 3.1EPSS 31.9%
Most severe rustfs (crates.io) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-45039: RustFS hard-coded default HMAC secret in internode RPC layercriticalCVSS 9.8
- CVE-2026-49991: RustFS path traversal in Snowball auto-extract featurehighCVSS 8.6
- CVE-2026-40937: RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhookshighCVSS 8.3EPSS 0.5%
- CVE-2026-55188: RustFS authorization bypass in ListRemoteTargetHandler replication APIhighCVSS 8.2
- CVE-2026-55189: rustfs RustFS missing authorization in FTP frontend object readshighCVSS 7.7
- CVE-2026-39360: RustFS missing authorization in multipart UploadPartCopymediumCVSS 4.3EPSS 0.3%
- CVE-2026-55838: RustFS missing authorization in metrics endpointmediumCVSS 4.3
- CVE-2025-68705: RustFS Path Traversal VulnerabilitymediumCVSS 4EPSS 7.4%
- CVE-2026-22782: RustFS's RPC signature verification logs shared secretmediumCVSS 4EPSS 0.5%
- CVE-2026-22042: RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege EscalationmediumCVSS 4EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/rustfs.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "rustfs (crates.io) vulnerabilities", https://junglewise.ai/threats/technologies/rustfs, 27 September 2026.