Unauthorized File Upload Vulnerability in RustFS Distributed Object Storage
CVE-2026-27607
Key Information:
Badges
What is CVE-2026-27607?
RustFS, a distributed object storage system, contains a vulnerability in its presigned POST uploads across specific alpha versions. This oversight allows attackers to circumvent restrictions on content-length and content-type, potentially enabling unauthorized file uploads that exceed established size limits and targeting arbitrary object keys. Such actions could lead to storage exhaustion, unauthorized access to sensitive data, and various security issues, thereby compromising the integrity of the system. The issue has been resolved in version 1.0.0-alpha.83.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rustfs >= 1.0.0-alpha.56, < 1.0.0-alpha.83
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
