rustfs records
12 published records for vendor rustfs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-862 Missing Authorization2
- CWE-269 Improper Privilege Management1
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2025-68926Proof of concept | RustFS has a gRPC Hardcoded Token Authentication Bypassrustfs · rustfs · CWE-287 | Critical9.8 | — | 31.9% | Dec 30, 2025 |
37Monitor | CVE-2025-68705Proof of concept | RustFS Path Traversal Vulnerabilityrustfs · rustfs · CWE-22 | High8.8 | — | 7.4% | Jan 7, 2026 |
36Monitor | CVE-2026-27607Proof of concept | RustFS's Missing Post Policy Validation leads to Arbitrary Object Writerustfs · rustfs · CWE-20 | Critical9.1 | — | 0.4% | Feb 24, 2026 |
33Monitor | CVE-2026-40937No exploit | RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooksrustfs · rustfs · CWE-862 | High8.3 | — | 0.5% | Apr 22, 2026 |
30Monitor | CVE-2026-21862No exploit | RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headersrustfs · rustfs · CWE-290 | High7.7 | — | 0.2% | Feb 3, 2026 |
27Monitor | CVE-2026-24762No exploit | RustFS Logs Sensitive Credentials in Plaintextrustfs · rustfs · CWE-532 | Medium6.9 | — | 0.3% | Feb 3, 2026 |
22Monitor | CVE-2026-22042No exploit | RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalationrustfs · rustfs · CWE-285 | Medium5.7 | — | 0.4% | Jan 8, 2026 |
22Monitor | CVE-2026-22043No exploit | RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Mintingrustfs · rustfs · CWE-269 | Medium5.7 | — | 0.4% | Jan 8, 2026 |
22Monitor | CVE-2025-69255No exploit | RustFS gRPC GetMetrics deserialization panic enables remote DoSrustfs · rustfs · CWE-755 | Medium5.5 | — | 0.3% | Jan 7, 2026 |
21Monitor | CVE-2026-27822No exploit | Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeoverrustfs · rustfs · CWE-79 | Medium5.4 | — | 0.4% | Feb 24, 2026 |
21Monitor | CVE-2026-39360No exploit | RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationrustfs · rustfs · CWE-862 | Medium5.3 | — | 0.3% | Apr 7, 2026 |
11Monitor | CVE-2026-22782No exploit | RustFS RPC signature verification logs shared secretrustfs · rustfs · CWE-532 | Low2.9 | — | 0.5% | Jan 16, 2026 |
- CVE-2025-6892649Plan
RustFS has a gRPC Hardcoded Token Authentication Bypass
CriticalCVSS 9.8Proof of conceptEPSS 32%rustfs · rustfsDec 30, 2025
- CVE-2025-6870537Monitor
RustFS Path Traversal Vulnerability
HighCVSS 8.8Proof of conceptEPSS 7%rustfs · rustfsJan 7, 2026
- CVE-2026-2760736Monitor
RustFS's Missing Post Policy Validation leads to Arbitrary Object Write
CriticalCVSS 9.1Proof of conceptEPSS 0%rustfs · rustfsFeb 24, 2026
- CVE-2026-4093733Monitor
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
HighCVSS 8.3No exploitEPSS 0%rustfs · rustfsApr 22, 2026
- CVE-2026-2186230Monitor
RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
HighCVSS 7.7No exploitEPSS 0%rustfs · rustfsFeb 3, 2026
- CVE-2026-2476227Monitor
RustFS Logs Sensitive Credentials in Plaintext
MediumCVSS 6.9No exploitEPSS 0%rustfs · rustfsFeb 3, 2026
- CVE-2026-2204222Monitor
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
MediumCVSS 5.7No exploitEPSS 0%rustfs · rustfsJan 8, 2026
- CVE-2026-2204322Monitor
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
MediumCVSS 5.7No exploitEPSS 0%rustfs · rustfsJan 8, 2026
- CVE-2025-6925522Monitor
RustFS gRPC GetMetrics deserialization panic enables remote DoS
MediumCVSS 5.5No exploitEPSS 0%rustfs · rustfsJan 7, 2026
- CVE-2026-2782221Monitor
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
MediumCVSS 5.4No exploitEPSS 0%rustfs · rustfsFeb 24, 2026
- CVE-2026-3936021Monitor
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
MediumCVSS 5.3No exploitEPSS 0%rustfs · rustfsApr 7, 2026
- CVE-2026-2278211Monitor
RustFS RPC signature verification logs shared secret
LowCVSS 2.9No exploitEPSS 1%rustfs · rustfsJan 16, 2026