Loading...
Skip to main content
crates.io (Rust)

rustfs Security Analysis

rustfs has 8 known security vulnerabilities in crates.io (Rust). Upgrade to version 1.0.0-alpha.98 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

8 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 1.0.0-alpha.98

Upgrading to 1.0.0-alpha.98 or later resolves all 8 known vulnerabilities in rustfs. Update Cargo.toml: rustfs = "1.0.0-alpha.98"

Is rustfs in your project?

Check if you're affected and upgrade to 1.0.0-alpha.98 to stay secure.

8
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

8 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2025-68926
RustFS has a gRPC Hardcoded Token Authentication Bypass
CRITICAL
All versions1.0.0-alpha.78
CVE-2026-27822
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
CRITICAL
All versions1.0.0-alpha.83
CVE-2026-40937
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
HIGH
All versionsNo fix available
CVE-2026-27607
RustFS: Missing Post Policy Validation leads to Arbitrary Object Write
HIGH
All versions1.0.0-alpha.83
CVE-2026-21862
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
HIGH
All versions1.0.0-alpha.78
GHSA-mm2q-qcmx-gw4w
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
HIGH
All versions1.0.0-alpha.98
CVE-2026-22043
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
MEDIUM
All versions1.0.0-alpha.79
CVE-2026-22042
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
MEDIUM
All versions1.0.0-alpha.79

About This Data

Vulnerability data for rustfs is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related crates.io (Rust) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of rustfs.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed