GHSA-hgpf-8634-g44c: Medium severity go/github.com/seaweedfs/seaweedfs vulnerability

Published Aug 28, 2026
·
Updated

Summary SeaweedFS routes requests signed with SigV4 service s3tables to the S3Tables management API. Authorization on that path collapsed account-less S3 identities into the shared admin account and failed open, so a user holding only ordinary S3 Read credentials — and no S3Tables-specific permission — could invoke S3Tables management operations such as GET /buckets and enumerate administrator-owned table bucket inventory (names and ARNs). The same handler backs the Iceberg REST catalog, which was affected by the same flaw.

Impact An authenticated low-privileged S3 user can cross the boundary between ordinary S3 object access and S3Tables management. Confirmed impact is disclosure of administrator-owned table bucket inventory (bucket names and ARNs); in shared or multi-tenant deployments this can reveal tenant naming and operational structure.

Affected versions SeaweedFS >= 4.08, < 4.34 (the S3Tables management API was introduced in 4.08).

Patched versions Fixed in 4.34 (#9961). Administrator status is now decided by the ACTIONADMIN capability rather than by a collapsed admin account id, S3Tables authorization no longer defaults to allow, and the tautological ListTableBuckets gate was removed. Related hardening of the same root cause landed in #9962, #9963, and #9971.

Workaround No configuration workaround — upgrade to 4.34 or later.

Credit Reported by TA-MU-TA.

Affected Software

1 affected componentFixes available
go/github.com/seaweedfs/seaweedfs>=0.0.0-20260128085517-09bb90e8dc16<0.0.0-20260614205536-b13463880c1f
0.0.0-20260614205536-b13463880c1f

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/seaweedfs/seaweedfs to a version that resolves this vulnerability.

    Fixed in 0.0.0-20260614205536-b13463880c1f
  2. Upgrade

    Upgrade SeaweedFS to a version that resolves this vulnerability.

    Fixed in 4.34Patch #9961

Event History

Aug 28, 2026
Advisory Published
via GitHub·10:16 PM
Data Sourced
via GitHub·10:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

SeaweedFS versions 4.08 through 4.33 are affected. The vulnerable S3Tables management API was introduced in 4.08, and version 4.34 contains the fix.

2

What access does an attacker need?

An attacker needs authenticated ordinary S3 credentials with Read access. They do not need S3Tables-specific permission or administrator privileges, and no user interaction is required.

3

What information could be exposed?

The confirmed impact is enumeration of administrator-owned table bucket inventory, including bucket names and ARNs. In shared or multi-tenant environments, this can disclose tenant naming and operational structure.

4

Are Iceberg REST catalog requests also affected?

Yes. The same vulnerable handler backs the Iceberg REST catalog, so it was affected by the same authorization flaw.

5

How can this be remediated?

Upgrade SeaweedFS to version 4.34. The fix bases administrator status on the ACTION_ADMIN capability and removes the default-allow behavior from S3Tables authorization.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203