Skip to content
Noroxi

rustfs records

12 published records for vendor rustfs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
83.3%
Median publish → KEV
No record has entered KEV

All records

12 records
  • RustFS has a gRPC Hardcoded Token Authentication Bypass

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    rustfs · rustfsDec 30, 2025

  • RustFS Path Traversal Vulnerability

    HighCVSS 8.8Proof of conceptEPSS 7%

    rustfs · rustfsJan 7, 2026

  • RustFS's Missing Post Policy Validation leads to Arbitrary Object Write

    CriticalCVSS 9.1Proof of conceptEPSS 0%

    rustfs · rustfsFeb 24, 2026

  • RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks

    HighCVSS 8.3No exploitEPSS 0%

    rustfs · rustfsApr 22, 2026

  • RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers

    HighCVSS 7.7No exploitEPSS 0%

    rustfs · rustfsFeb 3, 2026

  • RustFS Logs Sensitive Credentials in Plaintext

    MediumCVSS 6.9No exploitEPSS 0%

    rustfs · rustfsFeb 3, 2026

  • RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation

    MediumCVSS 5.7No exploitEPSS 0%

    rustfs · rustfsJan 8, 2026

  • RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting

    MediumCVSS 5.7No exploitEPSS 0%

    rustfs · rustfsJan 8, 2026

  • RustFS gRPC GetMetrics deserialization panic enables remote DoS

    MediumCVSS 5.5No exploitEPSS 0%

    rustfs · rustfsJan 7, 2026

  • Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover

    MediumCVSS 5.4No exploitEPSS 0%

    rustfs · rustfsFeb 24, 2026

  • RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration

    MediumCVSS 5.3No exploitEPSS 0%

    rustfs · rustfsApr 7, 2026

  • RustFS RPC signature verification logs shared secret

    LowCVSS 2.9No exploitEPSS 1%

    rustfs · rustfsJan 16, 2026