Количество 2
Количество 2
CVE-2026-21862
RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable client can spoof aws:SourceIp and satisfy IP-allowlist policies. This issue has been patched in version alpha.78.
GHSA-fc6g-2gcp-2qrq
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-21862 RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable client can spoof aws:SourceIp and satisfy IP-allowlist policies. This issue has been patched in version alpha.78. | 0% Низкий | 6 дней назад | ||
GHSA-fc6g-2gcp-2qrq RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers | 0% Низкий | 6 дней назад |
Уязвимостей на страницу