CVE-2026-73080
Last modified
CVE-2026-73080 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle.
Description
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and no target validation, allowing anyone who can reach a volume server's gRPC port to cause requests to arbitrary hosts, including loopback, link-local, RFC 1918, and cloud metadata endpoints such as 169.254.169.254, and read the response. On cloud deployments, this can disclose instance metadata and IAM credentials and reach otherwise unexposed internal services. The volume server gRPC plane is unauthenticated by default, and configuring documented JWT signing keys does not protect this RPC. This issue is fixed in version 4.24.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| seaweedfs | seaweedfs | < 4.24 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73080?
How severe is CVE-2026-73080?
How do I fix CVE-2026-73080?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73075Vim is an open source, command line text editor. From 9.2.04…4.6
- CVE-2026-73076Vim is an open source, command line text editor. Prior to 9.…8.4
- CVE-2026-73077Vim is an open source, command line text editor. Prior to 9.…8.4
- CVE-2026-73078Vim is an open source, command line text editor. Prior to 9.…8.6
- CVE-2026-73079Sub2API is an AI API gateway platform designed to distribute…8.5
- CVE-2026-7308An authenticated user with upload permission to a hosted rep…5.1
- CVE-2026-73081Activepieces is an open source AI workflow automation platfo…8.7
- CVE-2026-73082Activepieces is an open source AI workflow automation platfo…5.3
- CVE-2026-73083Activepieces is an open source AI workflow automation platfo…7.6
- CVE-2026-73084Activepieces is an open source AI workflow automation platfo…6.1
- CVE-2026-73085Audiobookshelf is a self-hosted audiobook and podcast server…5.3
- CVE-2026-73086nanoid is a secure, URL-friendly, unique string ID generator…7.4
Are you affected by CVE-2026-73080?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
