{"id":"CVE-2026-73080","aliases":["BIT-seaweedfs-2026-73080","GHSA-87fv-vqqr-m4jr","GO-2026-6219"],"url":"https://o3.security/vulnerability/CVE-2026-73080","summary":"SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle","details":"### Impact\n`VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing requests to arbitrary hosts — including loopback, link-local, RFC 1918, and cloud metadata endpoints such as `169.254.169.254` — and read the response back. On cloud deployments this discloses instance metadata and IAM credentials, and can be used to reach otherwise-unexposed internal services (SSRF with response read-back).\n\nThe volume server gRPC plane is unauthenticated on a default deployment, so no credentials are required. Configuring the documented JWT signing keys does not close it, because that hardening does not apply to this RPC.\n\n### Affected component\n- `weed/server/volume_grpc_remote.go` (`FetchAndWriteNeedle`)\n- `weed/remote_storage/s3/s3_storage_client.go`\n\n### Patches\nFixed in **4.24**. `FetchAndWriteNeedle` now requires admin authorization and refuses loopback / link-local / RFC 1918 / IMDS destinations through a guarded dialer that resolves the host itself and pins the resolved address for the duration of the request, defeating DNS-rebinding. The Rust volume server carries the equivalent endpoint validation.\n\n### Workarounds\nRestrict volume server gRPC ports to trusted hosts via firewall / network policy, and enable mTLS via `security.toml`.","published":"2026-08-11T15:57:10.809Z","modified":"2026-09-11T03:30:56.558899896Z","cvss":{"score":9.3,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"},"epss":{"score":0.00384,"percentile":0.32153,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/seaweedfs/seaweedfs","fixedVersion":"0.0.0-20260512171120-69da20bdaec9"}],"fix":{"url":"https://github.com/seaweedfs/seaweedfs/commit/69da20bdaec923e5a43d8aa71bf3c0a2051fc019","label":"seaweedfs/seaweedfs@69da20b"},"references":[{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/releases/tag/4.24"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73080.json"},{"type":"ADVISORY","url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-87fv-vqqr-m4jr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73080"},{"type":"FIX","url":"https://github.com/seaweedfs/seaweedfs/commit/69da20bdaec923e5a43d8aa71bf3c0a2051fc019"},{"type":"FIX","url":"https://github.com/seaweedfs/seaweedfs/pull/9441"},{"type":"PACKAGE","url":"https://github.com/seaweedfs/seaweedfs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:56.558899896Z"}}