


Perceptive Security
SOC/SIEM Consultancy

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping onl…
Published:
26 August 2026 at 00:00:00
Alert date:
27 August 2026 at 01:02:07
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Web Technologies
CVE-2026-77368 affects SeaweedFS version 4.39, a distributed storage system. The vulnerability exists in the filer's TUS resumable-upload handler, which only checks JWT allowed_prefixes scoping during session creation. HTTP verbs HEAD, PATCH, and DELETE operating on existing sessions by session ID never verify the stored target path against the caller's allowed prefixes. A low-privilege tenant who obtains another tenant's upload session identifier can inject arbitrary bytes via PATCH, causing files to land at out-of-scope paths. Attackers can also DELETE other tenants' sessions and HEAD them to read upload progress and size, defeating JWT prefix isolation. The vulnerability only impacts deployments using filer JWT signing with TUS uploads enabled. The issue has been patched in SeaweedFS version 4.40.
Technical details
Mitigation steps:
Affected products:
SeaweedFS 4.39
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-77368
https://github.com/seaweedfs/seaweedfs/commit/ce82e3a057080162a9fba11889157d2255815f71
https://github.com/seaweedfs/seaweedfs/commit/fa549e9c83b7799d512157d728f52052912831af
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-99q7-x53r-6j4g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
