PT-2026-70270 · Seaweedfs · Seaweedfs

CVE-2026-73080

·

Published

2026-08-11

·

Updated

2026-09-04

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SeaweedFS versions prior to 4.24
Description An issue exists in the VolumeServer.FetchAndWriteNeedle function within weed/server/volume grpc remote.go that fetches a remote endpoint provided by the caller via weed/remote storage/s3/s3 storage client.go and writes the response into a needle. Because the RPC lacks authentication and target validation, an attacker with access to the volume server's gRPC port can trigger requests to arbitrary hosts, including loopback, link-local, RFC 1918, and cloud metadata endpoints like 169.254.169.254. In cloud environments, this can lead to the disclosure of instance metadata and IAM credentials, or allow access to internal services that are not otherwise exposed. The volume server gRPC plane is unauthenticated by default, and the use of JWT signing keys does not mitigate this issue.
Recommendations Update to version 4.24.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-73080
CVE-2026-73080
GHSA-87FV-VQQR-M4JR
GO-2026-6219
OPENSUSE-SU-2026:21761-1

Affected Products

Seaweedfs