top of page
perceptive_background_267k.jpg

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping onl…

Published:

26 August 2026 at 00:00:00

Alert date:

27 August 2026 at 01:02:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Identity & Access, Web Technologies

CVE-2026-77368 affects SeaweedFS version 4.39, a distributed storage system. The vulnerability exists in the filer's TUS resumable-upload handler, which only checks JWT allowed_prefixes scoping during session creation. HTTP verbs HEAD, PATCH, and DELETE operating on existing sessions by session ID never verify the stored target path against the caller's allowed prefixes. A low-privilege tenant who obtains another tenant's upload session identifier can inject arbitrary bytes via PATCH, causing files to land at out-of-scope paths. Attackers can also DELETE other tenants' sessions and HEAD them to read upload progress and size, defeating JWT prefix isolation. The vulnerability only impacts deployments using filer JWT signing with TUS uploads enabled. The issue has been patched in SeaweedFS version 4.40.

Technical details

Mitigation steps:

Affected products:

SeaweedFS 4.39

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page