Seaweedfs

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-77611

    SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a different object with the same basename

    Last Modified: Aug 27, 2026
    Published: Aug 26, 2026

    CVE-2026-77317

    SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

    Last Modified: Aug 29, 2026
    Published: Aug 26, 2026

    CVE-2026-77298

    SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

    Last Modified: Aug 27, 2026
    Published: Aug 26, 2026

    CVE-2026-77368

    SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden Paths

    Last Modified: Aug 27, 2026
    Published: Aug 26, 2026

    CVE-2026-73080

    SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

    Last Modified: Aug 13, 2026
    Published: Aug 11, 2026
    Items Per Page