Seaweedfs is a distributed file-system and object-storage platform, with its vulnerability profile concentrated in the core Seaweedfs product itself. The durable signal centers on database-layer input handling, specifically SQL-injection weaknesses that arise in query construction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seaweedfs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54917CRITICAL SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construc | Jun 25, 2026 | 10.0 | 38 | NO | NO |
CVE-2026-58372HIGH SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single b | Jun 30, 2026 | 8.1 | 34 | NO | NO |
SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/javascript in the shared writeJson helper (weed/server/comm | Jun 30, 2026 | 3.1 | 22 | NO | NO |
CVE-2024-40120MEDIUM seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go. | May 16, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seaweedfs.
Media articles that mention a CVE ID that affects a product developed by Seaweedfs — matched by CVE ID, not by vendor name.