THREAT OPS › Threat News › [GHSA] GHSA-56wq-x3wv-3ff4 (high) — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
[GHSA] GHSA-56wq-x3wv-3ff4 (high) — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
GHSA-56wq-x3wv-3ff4 Severity: high CVE: CVE-2026-55874
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
### Summary The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy
Indicators of compromise
- b44cf51fe931bd75aa4d37ae766bea90d7f85ccdsha1
- CVE-2026-55874cve
- CVE-2026-54917cve
Original source: https://github.com/advisories/GHSA-56wq-x3wv-3ff4