SecAlerts
S

SeaweedFS

Security Risk Profile

57
/100
medium

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 16, 2025 to present

12
Total CVEs
9
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
57/100
medium
🆕 4Fresh (<7d)📈 6 in Last 30 Days

Severity Distribution

Critical
1
High
8
Medium
2
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
3
2
XSS
1
3
SQL Injection
1

Most Affected Products

1. seaweedfs seaweedfs14
2. go/github.com/seaweedfs/seaweedfs2
3. SeaweedFS1

Recent Vulnerabilities

See more →
CVE-2026-77611
CVSS 7.1high

SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a different object with the same basename

Aug 26, 2026🔧 No Patch
CVE-2026-77317
CVSS 8.1high

SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

Aug 26, 2026🔧 No Patch
CVE-2026-77298
CVSS 8.7high

SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

Aug 26, 2026🔧 No Patch
CVE-2026-77368
CVSS 7.6high

SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden Paths

Aug 26, 2026🔧 No Patch
CVE-2026-72921
CVSS 8.1high

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

Aug 11, 2026🔧 No Patch
CVE-2026-72920
CVSS 9.8critical

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

Aug 11, 2026🔧 No Patch
CVE-2026-55873
CVSS 4.3medium

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

Jul 8, 2026🔧 No Patch
CVE-2026-55874
CVSS 7.7high

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

Jul 8, 2026🔧 No Patch
CVE-2026-58372
CVSS 7.2high

SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys

Jun 30, 2026🔧 No Patch
CVE-2026-58371
CVSS 2.3low

SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback Parameter

Jun 30, 2026🔧 No Patch

Monitor SeaweedFS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

SeaweedFS Security Vulnerabilities & Risk Score | 12 CVEs | SecAlerts - SecAlerts