{"id":"CVE-2025-68671","aliases":["GHSA-f2ph-gc9m-q55f","GO-2026-4321"],"url":"https://o3.security/vulnerability/CVE-2025-68671","summary":"lakeFS is Missing Timestamp Validation in S3 Gateway Authentication","details":"### Impact\nLakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. An attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire.\n\n### Patches\nThis issue affects all versions of lakeFS up to and including v1.74.4.\n\nThe vulnerability has been fixed in version v1.75.0.\n\nUsers should upgrade to version v1.75.0.\n\n### Workarounds\n\nUntil upgraded, implement these mitigations:\n\n- **Use short-lived credentials** - Rotate access keys frequently and **deactivate old keys**. For regular requests, captured requests only work until rotation. For presigned URLs, they remain valid until the credentials used to create them are deactivated.\n- **Network controls** - Restrict S3 gateway access to trusted networks/IPs to limit where replay attacks can originate.\n\nNote: These workarounds reduce risk but do not fully eliminate the vulnerability.\n\n### References\n- Original issue: https://github.com/treeverse/lakeFS/issues/9599\n- AWS Signature V4 Documentation: https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html\n- AWS Signature V4 S3 Requests: https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html\n- AWS Signature V2 Documentation: https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-header-based-auth.html","published":"2026-01-15T22:35:44.495Z","modified":"2026-08-12T03:51:34.146943797Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":{"score":0.00248,"percentile":0.1583,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/treeverse/lakefs","fixedVersion":"1.75.0"}],"fix":{"url":"https://github.com/treeverse/lakeFS/commit/92966ae611d7f1a2bbe7fd56f9568c975aab2bd8","label":"treeverse/lakeFS@92966ae"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68671.json"},{"type":"ADVISORY","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-f2ph-gc9m-q55f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68671"},{"type":"REPORT","url":"https://github.com/treeverse/lakeFS/issues/9599"},{"type":"FIX","url":"https://github.com/treeverse/lakeFS/commit/92966ae611d7f1a2bbe7fd56f9568c975aab2bd8"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/pull/9710"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.146943797Z"}}