Ceph
Vendor:
First CVE: Dec 3, 2015 · Active for 10 years
17
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ceph over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2015
10 years ago
Most Recent CVE
Nov 12, 2025
253 days ago
CVE Severity & Scoring
Ceph17 CVEs
59%
41%
All CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (17.6%)
Network10 (58.8%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network3 (17.6%)
Attack Complexity
Low15 (88.2%)
High1 (5.9%)
Unknown1 (5.9%)
User Interaction
None14 (82.4%)
Unknown1 (5.9%)
Required2 (11.8%)
Privileges Required
Low8 (47.1%)
High1 (5.9%)
None7 (41.2%)
Unknown1 (5.9%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25660HIGH A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay | Nov 23, 2020 | 8.8 | 27 | NO | NO |
CVE-2022-3650HIGH A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged informatio | Jan 17, 2023 | 7.8 | 26 | NO | NO |
CVE-2024-47866HIGH Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an em | Nov 12, 2025 | 7.5 | 25 | NO | NO |
CVE-2018-7262HIGH In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of | Mar 19, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-16889HIGH Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v | Jan 28, 2019 | 7.5 | 24 | NO | NO |
CVE-2021-3524MEDIUM A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS Expo | May 17, 2021 | 6.5 | 23 | NO | NO |
CVE-2020-27781HIGH User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request ac | Dec 18, 2020 | 7.1 | 23 | NO | NO |
CVE-2018-16846MEDIUM It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices. | Jan 15, 2019 | 6.5 | 23 | NO | NO |
CVE-2018-1128HIGH It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is | Jul 10, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-16818MEDIUM RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necess | Dec 20, 2017 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ceph
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 16.2.9 | 1 | 7.8 | 0.3% | 0 | 0 |
| 13.0.1 | 1 | 7.5 | 3.0% | 0 | 0 |
| 13.0.0 | 1 | 7.5 | 3.0% | 0 | 0 |