Vendor
critical
advisory
SeaweedFS Unauthenticated IAM gRPC Service Authentication Bypass
2 TTPs 1 CVESeaweedFS versions prior to 4.24 contain an authentication bypass in the IAM gRPC service, allowing unauthenticated network actors to mint administrative S3 credentials and gain full control over object storage via CVE-2026-72920.
SeaweedFS
2t
1c
critical
advisory
Unauthenticated SSRF in SeaweedFS VolumeServer.FetchAndWriteNeedle
1 rule 3 TTPs 1 CVESeaweedFS versions prior to 4.24 are vulnerable to unauthenticated SSRF via the VolumeServer.FetchAndWriteNeedle RPC, allowing attackers to access internal services and cloud metadata endpoints.
SeaweedFS +1
1r
3t
1c
updated