THREAT OPS › Threat News › [GHSA] GHSA-87fv-vqqr-m4jr (critical) — SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
[GHSA] GHSA-87fv-vqqr-m4jr (critical) — SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
GHSA-87fv-vqqr-m4jr Severity: critical CVE: CVE-2026-73080
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume serv
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73080cve
Original source: https://github.com/advisories/GHSA-87fv-vqqr-m4jr