| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-333v-68xh-8mmq | RustFS's RPC signature verification logs shared secret |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha10:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha11:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha12:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha13:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha14:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha15:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha16:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha17:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha18:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha19:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha1:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha20:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha21:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha22:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha23:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha24:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha25:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha26:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha27:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha28:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha29:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha2:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha30:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha31:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha32:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha33:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha34:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha35:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha36:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha37:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha38:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha39:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha3:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha40:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha41:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha42:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha43:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha44:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha45:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha46:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha47:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha48:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha49:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha4:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha50:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha51:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha52:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha53:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha54:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha55:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha56:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha57:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha58:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha59:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha5:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha60:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha61:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha62:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha63:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha64:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha65:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha66:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha67:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha68:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha69:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha6:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha70:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha71:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha72:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha73:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha74:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha75:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha76:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha77:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha78:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha79:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha7:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha8:*:*:*:rust:*:* cpe:2.3:a:rustfs:rustfs:1.0.0:alpha9:*:*:*:rust:*:* |
|
| Metrics |
cvssV3_1
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustfs
Rustfs rustfs |
|
| Vendors & Products |
Rustfs
Rustfs rustfs |
Fri, 16 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid signature branch logs sensitive data. This log line includes secret and expected_signature, both derived from the shared HMAC key. Any invalidly signed request triggers this path. The function is reachable from RPC and admin request handlers. This vulnerability is fixed in 1.0.0-alpha.80. | |
| Title | RustFS RPC signature verification logs shared secret | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-16T16:36:08.520Z
Reserved: 2026-01-09T18:27:19.388Z
Link: CVE-2026-22782
Updated: 2026-01-16T16:35:44.458Z
Status : Analyzed
Published: 2026-01-16T17:15:54.343
Modified: 2026-02-09T20:47:26.030
Link: CVE-2026-22782
No data.
OpenCVE Enrichment
Updated: 2026-01-19T09:20:57Z
Github GHSA