Vendor
SeaweedFS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 12 vulnerabilities in SeaweedFS: 0 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-72921, was published on 2 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 2
- Exploited in the wild
- 0
About SeaweedFS
SeaweedFS is an open-source distributed storage system for blobs, objects, files, and data lake.
SeaweedFS technologies
Latest SeaweedFS vulnerabilities
- CVE-2026-72921: SeaweedFS Filer JWT authorization bypass in allowed_prefixeshighCVSS 8.1EPSS 0.4%
- CVE-2026-72920: SeaweedFS unauthenticated filer IAM gRPC service authentication bypasscriticalCVSS 9.8EPSS 0.8%
- CVE-2026-77611: SeaweedFS S3 object-scope bypass in PutObjectAclhighCVSS 7.1EPSS 0.4%
- CVE-2026-77368: SeaweedFS TUS resumable-upload JWT authorization bypasshighCVSS 7.6EPSS 0.4%
- CVE-2026-77317: SeaweedFS SFTP path ACL literal prefix matching bypasshighCVSS 8.1EPSS 0.4%
- CVE-2026-77298: SeaweedFS S3 OIDC Bearer authentication bypasses role trust policyinfoCVSS 7.5EPSS 0.4%
- CVE-2026-73080: SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in…criticalCVSS 9.3EPSS 0.5%
- CVE-2026-55874: SeaweedFS path traversal in S3 API X-Amz-Copy-Source headerhighCVSS 7.7EPSS 0.6%
- CVE-2026-55873: SeaweedFS incorrect authorization in S3Tables management APImediumCVSS 4.3EPSS 0.3%
- CVE-2026-58372: SeaweedFS path traversal in S3 gateway DeleteMultipleObjectsHandlerhighCVSS 8.1
- CVE-2026-58371: SeaweedFS information disclosure via unvalidated JSONP callbacklowCVSS 3.1
- CVE-2026-54917: SeaweedFS path traversal in S3 and Iceberg gatewayshighCVSS 7.8EPSS 0.4%
Most severe SeaweedFS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-72920: SeaweedFS unauthenticated filer IAM gRPC service authentication bypasscriticalCVSS 9.8EPSS 0.8%
- CVE-2026-73080: SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in…criticalCVSS 9.3EPSS 0.5%
- CVE-2026-72921: SeaweedFS Filer JWT authorization bypass in allowed_prefixeshighCVSS 8.1EPSS 0.4%
- CVE-2026-77317: SeaweedFS SFTP path ACL literal prefix matching bypasshighCVSS 8.1EPSS 0.4%
- CVE-2026-58372: SeaweedFS path traversal in S3 gateway DeleteMultipleObjectsHandlerhighCVSS 8.1
- CVE-2026-54917: SeaweedFS path traversal in S3 and Iceberg gatewayshighCVSS 7.8EPSS 0.4%
- CVE-2026-55874: SeaweedFS path traversal in S3 API X-Amz-Copy-Source headerhighCVSS 7.7EPSS 0.6%
- CVE-2026-77368: SeaweedFS TUS resumable-upload JWT authorization bypasshighCVSS 7.6EPSS 0.4%
- CVE-2026-77611: SeaweedFS S3 object-scope bypass in PutObjectAclhighCVSS 7.1EPSS 0.4%
- CVE-2026-55873: SeaweedFS incorrect authorization in S3Tables management APImediumCVSS 4.3EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 4 | 0 | |
| 31 Aug 2026 | 2 | 1 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/seaweedfs.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SeaweedFS vulnerabilities", https://junglewise.ai/threats/vendors/seaweedfs, 26 September 2026.