THREAT OPS › Threat News › [GHSA] GHSA-xwwr-4h3p-r22c (critical) — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
[GHSA] GHSA-xwwr-4h3p-r22c (critical) — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
GHSA-xwwr-4h3p-r22c Severity: critical CVE: CVE-2026-88018
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
### Summary `rclone serve s3`'s handler chain, when `--auth-proxy` is configured, is (outermost first): `authPairMiddleware` -> `proxyAuthMiddleware` -> gofakes3's own SigV4-verifying handler.
`authPairMiddleware` parses the accessKeyID s
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-88018cve
Original source: https://github.com/advisories/GHSA-xwwr-4h3p-r22c