{"schema_version":1,"title":"SeaweedFS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in SeaweedFS: 0 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-72921, was published on 2 September 2026.","url":"https://junglewise.ai/threats/technologies/seaweedfs","json_url":"https://junglewise.ai/threats/technologies/seaweedfs.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/seaweedfs","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":12,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":11,"last_365_days":12},"latest":[{"cve":"CVE-2026-72921","cvss":8.1,"epss":0.0043,"slug":"cve-2026-72921-seaweedfs-filer-jwt-authorization-bypass-in-allowed-prefixes","title":"SeaweedFS Filer JWT authorization bypass in allowed_prefixes","severity":"high","exploited":false,"published_at":"2026-09-02T23:42:05+00:00","url":"https://junglewise.ai/threats/cve-2026-72921-seaweedfs-filer-jwt-authorization-bypass-in-allowed-prefixes"},{"cve":"CVE-2026-72920","cvss":9.8,"epss":0.0078,"slug":"cve-2026-72920-seaweedfs-unauthenticated-filer-iam-grpc-service-authentication","title":"SeaweedFS unauthenticated filer IAM gRPC service authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-02T14:51:58+00:00","url":"https://junglewise.ai/threats/cve-2026-72920-seaweedfs-unauthenticated-filer-iam-grpc-service-authentication"},{"cve":"CVE-2026-77611","cvss":7.1,"epss":0.0038,"slug":"cve-2026-77611-seaweedfs-s3-object-scope-bypass-in-putobjectacl","title":"SeaweedFS S3 object-scope bypass in PutObjectAcl","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:30.007+00:00","url":"https://junglewise.ai/threats/cve-2026-77611-seaweedfs-s3-object-scope-bypass-in-putobjectacl"},{"cve":"CVE-2026-77368","cvss":7.6,"epss":0.0038,"slug":"cve-2026-77368-seaweedfs-tus-resumable-upload-jwt-authorization-bypass","title":"SeaweedFS TUS resumable-upload JWT authorization bypass","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:29.86+00:00","url":"https://junglewise.ai/threats/cve-2026-77368-seaweedfs-tus-resumable-upload-jwt-authorization-bypass"},{"cve":"CVE-2026-77317","cvss":8.1,"epss":0.0036,"slug":"cve-2026-77317-seaweedfs-sftp-path-acl-literal-prefix-matching-bypass","title":"SeaweedFS SFTP path ACL literal prefix matching bypass","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:29.717+00:00","url":"https://junglewise.ai/threats/cve-2026-77317-seaweedfs-sftp-path-acl-literal-prefix-matching-bypass"},{"cve":"CVE-2026-77298","cvss":7.5,"epss":0.004,"slug":"cve-2026-77298-seaweedfs-s3-oidc-bearer-authentication-bypasses-role-trust","title":"SeaweedFS S3 OIDC Bearer authentication bypasses role trust policy","severity":"info","exploited":false,"published_at":"2026-08-26T22:16:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-77298-seaweedfs-s3-oidc-bearer-authentication-bypasses-role-trust"},{"cve":"CVE-2026-73080","cvss":9.3,"epss":0.0053,"slug":"cve-2026-73080-seaweedfs-unauthenticated-ssrf-in-volumeserver","title":"SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a ca","severity":"critical","exploited":false,"published_at":"2026-08-11T16:17:39.857+00:00","url":"https://junglewise.ai/threats/cve-2026-73080-seaweedfs-unauthenticated-ssrf-in-volumeserver"},{"cve":"CVE-2026-55874","cvss":7.7,"epss":0.0061,"slug":"cve-2026-55874-seaweedfs-path-traversal-in-s3-api-x-amz-copy-source-header","title":"SeaweedFS path traversal in S3 API X-Amz-Copy-Source header","severity":"high","exploited":false,"published_at":"2026-07-08T15:16:30.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55874-seaweedfs-path-traversal-in-s3-api-x-amz-copy-source-header"},{"cve":"CVE-2026-55873","cvss":4.3,"epss":0.0034,"slug":"cve-2026-55873-seaweedfs-incorrect-authorization-in-s3tables-management-api","title":"SeaweedFS incorrect authorization in S3Tables management API","severity":"medium","exploited":false,"published_at":"2026-07-08T15:16:30.19+00:00","url":"https://junglewise.ai/threats/cve-2026-55873-seaweedfs-incorrect-authorization-in-s3tables-management-api"},{"cve":"CVE-2026-58372","cvss":8.1,"slug":"cve-2026-58372-seaweedfs-path-traversal-in-s3-gateway","title":"SeaweedFS path traversal in S3 gateway DeleteMultipleObjectsHandler","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:25.45+00:00","url":"https://junglewise.ai/threats/cve-2026-58372-seaweedfs-path-traversal-in-s3-gateway"},{"cve":"CVE-2026-58371","cvss":3.1,"slug":"cve-2026-58371-seaweedfs-information-disclosure-via-unvalidated-jsonp-callback","title":"SeaweedFS information disclosure via unvalidated JSONP callback","severity":"low","exploited":false,"published_at":"2026-06-30T17:16:25.113+00:00","url":"https://junglewise.ai/threats/cve-2026-58371-seaweedfs-information-disclosure-via-unvalidated-jsonp-callback"},{"cve":"CVE-2026-54917","cvss":7.8,"epss":0.0038,"slug":"cve-2026-54917-seaweedfs-path-traversal-in-s3-and-iceberg-gateways","title":"SeaweedFS path traversal in S3 and Iceberg gateways","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:42.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54917-seaweedfs-path-traversal-in-s3-and-iceberg-gateways"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"SeaweedFS","slug":"seaweedfs","vendor":{"name":"SeaweedFS","slug":"seaweedfs","url":"https://junglewise.ai/threats/vendors/seaweedfs"},"aliases":[],"category":"service","url":"https://junglewise.ai/threats/technologies/seaweedfs"},"most_severe":[{"cve":"CVE-2026-72920","cvss":9.8,"epss":0.0078,"slug":"cve-2026-72920-seaweedfs-unauthenticated-filer-iam-grpc-service-authentication","title":"SeaweedFS unauthenticated filer IAM gRPC service authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-02T14:51:58+00:00","url":"https://junglewise.ai/threats/cve-2026-72920-seaweedfs-unauthenticated-filer-iam-grpc-service-authentication"},{"cve":"CVE-2026-73080","cvss":9.3,"epss":0.0053,"slug":"cve-2026-73080-seaweedfs-unauthenticated-ssrf-in-volumeserver","title":"SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a ca","severity":"critical","exploited":false,"published_at":"2026-08-11T16:17:39.857+00:00","url":"https://junglewise.ai/threats/cve-2026-73080-seaweedfs-unauthenticated-ssrf-in-volumeserver"},{"cve":"CVE-2026-72921","cvss":8.1,"epss":0.0043,"slug":"cve-2026-72921-seaweedfs-filer-jwt-authorization-bypass-in-allowed-prefixes","title":"SeaweedFS Filer JWT authorization bypass in allowed_prefixes","severity":"high","exploited":false,"published_at":"2026-09-02T23:42:05+00:00","url":"https://junglewise.ai/threats/cve-2026-72921-seaweedfs-filer-jwt-authorization-bypass-in-allowed-prefixes"},{"cve":"CVE-2026-77317","cvss":8.1,"epss":0.0036,"slug":"cve-2026-77317-seaweedfs-sftp-path-acl-literal-prefix-matching-bypass","title":"SeaweedFS SFTP path ACL literal prefix matching bypass","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:29.717+00:00","url":"https://junglewise.ai/threats/cve-2026-77317-seaweedfs-sftp-path-acl-literal-prefix-matching-bypass"},{"cve":"CVE-2026-58372","cvss":8.1,"slug":"cve-2026-58372-seaweedfs-path-traversal-in-s3-gateway","title":"SeaweedFS path traversal in S3 gateway DeleteMultipleObjectsHandler","severity":"high","exploited":false,"published_at":"2026-06-30T17:16:25.45+00:00","url":"https://junglewise.ai/threats/cve-2026-58372-seaweedfs-path-traversal-in-s3-gateway"},{"cve":"CVE-2026-54917","cvss":7.8,"epss":0.0038,"slug":"cve-2026-54917-seaweedfs-path-traversal-in-s3-and-iceberg-gateways","title":"SeaweedFS path traversal in S3 and Iceberg gateways","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:42.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54917-seaweedfs-path-traversal-in-s3-and-iceberg-gateways"},{"cve":"CVE-2026-55874","cvss":7.7,"epss":0.0061,"slug":"cve-2026-55874-seaweedfs-path-traversal-in-s3-api-x-amz-copy-source-header","title":"SeaweedFS path traversal in S3 API X-Amz-Copy-Source header","severity":"high","exploited":false,"published_at":"2026-07-08T15:16:30.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55874-seaweedfs-path-traversal-in-s3-api-x-amz-copy-source-header"},{"cve":"CVE-2026-77368","cvss":7.6,"epss":0.0038,"slug":"cve-2026-77368-seaweedfs-tus-resumable-upload-jwt-authorization-bypass","title":"SeaweedFS TUS resumable-upload JWT authorization bypass","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:29.86+00:00","url":"https://junglewise.ai/threats/cve-2026-77368-seaweedfs-tus-resumable-upload-jwt-authorization-bypass"},{"cve":"CVE-2026-77611","cvss":7.1,"epss":0.0038,"slug":"cve-2026-77611-seaweedfs-s3-object-scope-bypass-in-putobjectacl","title":"SeaweedFS S3 object-scope bypass in PutObjectAcl","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:30.007+00:00","url":"https://junglewise.ai/threats/cve-2026-77611-seaweedfs-s3-object-scope-bypass-in-putobjectacl"},{"cve":"CVE-2026-55873","cvss":4.3,"epss":0.0034,"slug":"cve-2026-55873-seaweedfs-incorrect-authorization-in-s3tables-management-api","title":"SeaweedFS incorrect authorization in S3Tables management API","severity":"medium","exploited":false,"published_at":"2026-07-08T15:16:30.19+00:00","url":"https://junglewise.ai/threats/cve-2026-55873-seaweedfs-incorrect-authorization-in-s3tables-management-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}