THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-87fv-vqqr-m4jr (critical) — SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

[GHSA] GHSA-87fv-vqqr-m4jr (critical) — SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

medgithub_advisoriesPublished 2026-08-11

GHSA-87fv-vqqr-m4jr Severity: critical CVE: CVE-2026-73080

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume serv

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-87fv-vqqr-m4jr