CVE Tools

Rustfs

8 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.

Rustfs CVEs per month

May 2026 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Rustfs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0580

Products

The products that kept showing up in Rustfs's monthly top three, with their CVEs summed over those months.

  1. Rustfs81 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Rustfs.

  1. CVE-2026-73290RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback5.3
  2. CVE-2026-73289RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions8.1
  3. CVE-2026-73288RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted—
  4. CVE-2026-73287RustFS: FTPS MKD bypasses IAM CreateBucket authorization5.4
  5. CVE-2026-73286RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions8.1
  6. CVE-2026-73285RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged7.5
  7. CVE-2026-73284RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts8.8
  8. CVE-2026-73265RustFS: Version-specific object reads authorize the non-version action6.5
  9. CVE-2026-62378RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover9.0
  10. CVE-2026-55188RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials8.2
  11. CVE-2026-49991RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection8.6
  12. CVE-2026-55189RustFS: FTP frontend skips IAM authorization on object reads7.7
  13. CVE-2026-55838RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics4.3
  14. CVE-2026-45043RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root—
  15. CVE-2026-46685RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console—

The record

Peak rank
#177 in May 2026
Busiest month shown
May 2026, 8 CVEs
Months with a KEV entry
0 since May 2026
Monthly snapshots
1 since 2026
Rustfs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store