SecAlerts
R

RustFS

Security Risk Profile

53
/100
medium

Security Risk Score

Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 30, 2025 to present

23
Total CVEs
18
Critical+High
0
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
8.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
53/100
medium
📈 1 in Last 30 Days

Severity Distribution

Critical
8
High
10
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
Path Traversal
2
3
Infoleak
1
4
SSRF
1
5
CRLF Injection
1

Most Affected Products

1. RustFS Rustfs Rust869
2. RustFS RustFS15
3. rust/rustfs12
4. RustFS RustFS Console1
5. RustFS Snowball auto-extract1

Recent Vulnerabilities

See more →
CVE-2026-73286
CVSS 8.1high

RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions

Aug 12, 2026🔧 No Patch
CVE-2026-62378
CVSS 9.0critical

RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover

Jul 15, 2026🔧 No Patch
CVE-2026-49991
CVSS 8.6high

RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection

Jun 26, 2026🔧 No Patch
CVE-2026-45043
CVSS 9.3critical

RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root

May 29, 2026🔧 No Patch
CVE-2026-46685
CVSS 6.0medium

RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console

May 28, 2026🔧 No Patch
CVE-2026-45039
CVSS 9.8critical

RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation

May 28, 2026🔧 No Patch
CVE-2026-45040
CVSS 5.3medium

RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]

May 28, 2026🔧 No Patch
CVE-2026-45041
CVSS 8.7high

RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery

May 28, 2026🔧 No Patch
CVE-2026-45042
CVSS 7.1high

RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source

May 28, 2026🔧 No Patch
CVE-2026-45044
CVSS 8.8high

RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers

May 28, 2026🔧 No Patch

Monitor RustFS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

RustFS Security Vulnerabilities & Risk Score | 23 CVEs | SecAlerts - SecAlerts