CVE-2026-73290: RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policyallowed path applies denyanonymoustabledataplaneifneeded and RestrictPublicBuckets, so a bucket that permits anonymous listing can continue exposing version listings after an operator enables the public-access control. The bypass affects GET /<bucket>?versions= and can disclose object version metadata even though equivalent GetObject requests are denied. This issue is fixed in version 1.0.0-beta.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rustfsto a version that resolves this vulnerability.Fixed in 1.0.0-beta.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73290?
The severity of CVE-2026-73290 is medium with a score of 5.3.
How do I fix CVE-2026-73290?
To fix CVE-2026-73290, update RustFS to version 1.0.0-beta.12 or later.
What components are affected by CVE-2026-73290?
CVE-2026-73290 affects the RustFS distributed object storage system.
What exploit does CVE-2026-73290 introduce?
CVE-2026-73290 allows anonymous ListObjectVersions requests to bypass the RestrictPublicBuckets setting.
What versions of RustFS are vulnerable to CVE-2026-73290?
Versions of RustFS prior to 1.0.0-beta.12 are vulnerable to CVE-2026-73290.