THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-56wq-x3wv-3ff4 (high) — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

[GHSA] GHSA-56wq-x3wv-3ff4 (high) — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

highgithub_advisoriesPublished 2026-08-28

GHSA-56wq-x3wv-3ff4 Severity: high CVE: CVE-2026-55874

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

### Summary The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy

Indicators of compromise

Original source: https://github.com/advisories/GHSA-56wq-x3wv-3ff4