Ceph
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 38 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 8, 2015 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery
[OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Ceph 20.2.4 and Ceph 19.2.6 aleased with 4 security fixes.
CVE-2024-47866 Ceph: RGW DoS via improper input validation.
RGW DoS attack with empty HTTP header in S3 object copy
Ceph: Incorct usage of certificate checking via Pybind
ceph: avoid kernel BUG for encrypted inode with unaligned file size
CVE-2025-52555 Ceph: CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS
Monitor Ceph in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.