{"id":"CVE-2025-64179","aliases":["GHSA-h238-5mwf-8xw8","GO-2025-4090"],"url":"https://o3.security/vulnerability/CVE-2025-64179","summary":"lakeFS: Unauthenticated access to API usage metrics","details":"### Impact\n\nMissing authentication in the `/api/v1/usage-report/summary` endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is disclosed, the endpoint may reveal information about service activity or uptime.\n\n### Patches\nUpgrade to >v1.70.1\n\n### Workarounds\n\nAny **ONE** of these is sufficient to block this reporting:\n- Disable usage reporting by setting configuration option `usage_report.enabled` or environment variable `LAKEFS_USAGE_REPORT_ENABLED` to `false`.\n- Using load-balancer or application level firewall - blocking the request route /api/v1/usage-report/summary.","published":"2025-11-06T21:57:18.234Z","modified":"2026-08-12T03:51:36.550902813Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/treeverse/lakefs","fixedVersion":"1.71.0"}],"fix":{"url":"https://github.com/treeverse/lakeFS/commit/1c8adab852dac2387fcb00a256402b308a610c60","label":"treeverse/lakeFS@1c8adab"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64179.json"},{"type":"ADVISORY","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-h238-5mwf-8xw8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64179"},{"type":"FIX","url":"https://github.com/treeverse/lakeFS/commit/1c8adab852dac2387fcb00a256402b308a610c60"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.550902813Z"}}