Rustfs is a modestly represented file-system implementation that punches above its volume in the vulnerability landscape, reflecting either deep deployment in critical infrastructure or focused security research attention. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and demonstrate a moderate tendency toward public exploit availability, concentrated across authorization and access-control weakness classes including improper privilege boundaries, authentication bypass, and credential-handling flaws that are characteristic of security-sensitive storage layers. Defenders should treat this vendor's advisories as high-priority for any systems relying on its file-system implementation; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rustfs over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68926CRITICAL RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc" | Dec 30, 2025 | 9.8 | 64 | NO | YES |
CVE-2025-68705CRITICAL RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_fi | Jan 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-27607CRITICAL RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads | Feb 25, 2026 | 9.1 | 30 | NO | NO |
CVE-2026-22043CRITICAL RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted | Jan 8, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-40937HIGH RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a | Apr 22, 2026 | 8.3 | 28 | NO | NO |
CVE-2026-22042HIGH RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `Imp | Jan 8, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-27822MEDIUM RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an atta | Feb 25, 2026 | 5.4 | 26 | NO | NO |
CVE-2026-22782HIGH RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and exp | Jan 16, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-24762HIGH RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) t | Feb 3, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-21862HIGH RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwa | Feb 3, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rustfs.
Media articles that mention a CVE ID that affects a product developed by Rustfs — matched by CVE ID, not by vendor name.