GO-2026-6361
Dashboard / Vulnerabilities / GO-2026-6361
GO-2026-6361
Summary: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
Details: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
References: https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-gv5w-hfx8-8cwq, https://nvd.nist.gov/vuln/detail/CVE-2026-72921, https://github.com/seaweedfs/seaweedfs/commit/05ed5c9ae8a2a45101b52b61d02f170d20d587ff, https://github.com/seaweedfs/seaweedfs/pull/9439, https://github.com/seaweedfs/seaweedfs/releases/tag/4.24
Affected packages
Package
Name: github.com/seaweedfs/seaweedfs
Purl: pkg:golang/github.com/seaweedfs/seaweedfs
Affected ranges
Type: SEMVER
Events:
