THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xwwr-4h3p-r22c (critical) — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

[GHSA] GHSA-xwwr-4h3p-r22c (critical) — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

medgithub_advisoriesPublished 2026-09-10

GHSA-xwwr-4h3p-r22c Severity: critical CVE: CVE-2026-88018

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

### Summary `rclone serve s3`'s handler chain, when `--auth-proxy` is configured, is (outermost first): `authPairMiddleware` -> `proxyAuthMiddleware` -> gofakes3's own SigV4-verifying handler.

`authPairMiddleware` parses the accessKeyID s

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xwwr-4h3p-r22c