CVE Tools

Ceph

6 CVEs tracked since 2015. Since Jun 2015, none of them reached CISA KEV.

Ceph CVEs per month

Jun 2015 to Jul 2018. Point at a month, or focus the strip and use the arrow keys.
Ceph CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0620
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-1210
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0730

Products

The products that kept showing up in Ceph's monthly top three, with their CVEs summed over those months.

  1. Ceph42 months
  2. Ceph-deploy21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ceph.

  1. CVE-2026-54330Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation8.1
  2. CVE-2026-50152Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users9.1
  3. CVE-2026-39944Ceph: CephX AES Authentication error8.8
  4. CVE-2025-30156Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery8.9
  5. CVE-2024-47866RGW DoS attack with empty HTTP header in S3 object copy7.5
  6. CVE-2024-48916Ceph is vulnerable to authentication bypass through RadosGW8.1
  7. CVE-2025-52555CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS6.5
  8. CVE-2020-1716A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse th...8.8
  9. CVE-2020-25677A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information wi...5.5
  10. CVE-2020-1700A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanen...6.5
  11. CVE-2019-10222A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and te...7.5
  12. CVE-2019-3821A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exha...7.5
  13. CVE-2017-7519In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.2.3
  14. CVE-2018-10861A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches m...8.1
  15. CVE-2018-1129A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able t...6.5

The record

Peak rank
#55 in Jun 2015
Busiest month shown
Jul 2018, 3 CVEs
Months with a KEV entry
0 since Jun 2015
Monthly snapshots
3 since 2015
Ceph's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store