CVE-2026-22782

EUVD-2026-2923
RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid signature branch logs sensitive data. This log line includes secret and expected_signature, both derived from the shared HMAC key. Any invalidly signed request triggers this path. The function is reachable from RPC and admin request handlers. This vulnerability is fixed in 1.0.0-alpha.80.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
rustfsrustfs
1.0.0:alpha1
rustfsrustfs
1.0.0:alpha10
rustfsrustfs
1.0.0:alpha11
rustfsrustfs
1.0.0:alpha12
rustfsrustfs
1.0.0:alpha13
rustfsrustfs
1.0.0:alpha14
rustfsrustfs
1.0.0:alpha15
rustfsrustfs
1.0.0:alpha16
rustfsrustfs
1.0.0:alpha17
rustfsrustfs
1.0.0:alpha18
rustfsrustfs
1.0.0:alpha19
rustfsrustfs
1.0.0:alpha2
rustfsrustfs
1.0.0:alpha20
rustfsrustfs
1.0.0:alpha21
rustfsrustfs
1.0.0:alpha22
rustfsrustfs
1.0.0:alpha23
rustfsrustfs
1.0.0:alpha24
rustfsrustfs
1.0.0:alpha25
rustfsrustfs
1.0.0:alpha26
rustfsrustfs
1.0.0:alpha27
rustfsrustfs
1.0.0:alpha28
rustfsrustfs
1.0.0:alpha29
rustfsrustfs
1.0.0:alpha3
rustfsrustfs
1.0.0:alpha30
rustfsrustfs
1.0.0:alpha31
rustfsrustfs
1.0.0:alpha32
rustfsrustfs
1.0.0:alpha33
rustfsrustfs
1.0.0:alpha34
rustfsrustfs
1.0.0:alpha35
rustfsrustfs
1.0.0:alpha36
rustfsrustfs
1.0.0:alpha37
rustfsrustfs
1.0.0:alpha38
rustfsrustfs
1.0.0:alpha39
rustfsrustfs
1.0.0:alpha4
rustfsrustfs
1.0.0:alpha40
rustfsrustfs
1.0.0:alpha41
rustfsrustfs
1.0.0:alpha42
rustfsrustfs
1.0.0:alpha43
rustfsrustfs
1.0.0:alpha44
rustfsrustfs
1.0.0:alpha45
rustfsrustfs
1.0.0:alpha46
rustfsrustfs
1.0.0:alpha47
rustfsrustfs
1.0.0:alpha48
rustfsrustfs
1.0.0:alpha49
rustfsrustfs
1.0.0:alpha5
rustfsrustfs
1.0.0:alpha50
rustfsrustfs
1.0.0:alpha51
rustfsrustfs
1.0.0:alpha52
rustfsrustfs
1.0.0:alpha53
rustfsrustfs
1.0.0:alpha54
rustfsrustfs
1.0.0:alpha55
rustfsrustfs
1.0.0:alpha56
rustfsrustfs
1.0.0:alpha57
rustfsrustfs
1.0.0:alpha58
rustfsrustfs
1.0.0:alpha59
rustfsrustfs
1.0.0:alpha6
rustfsrustfs
1.0.0:alpha60
rustfsrustfs
1.0.0:alpha61
rustfsrustfs
1.0.0:alpha62
rustfsrustfs
1.0.0:alpha63
rustfsrustfs
1.0.0:alpha64
rustfsrustfs
1.0.0:alpha65
rustfsrustfs
1.0.0:alpha66
rustfsrustfs
1.0.0:alpha67
rustfsrustfs
1.0.0:alpha68
rustfsrustfs
1.0.0:alpha69
rustfsrustfs
1.0.0:alpha7
rustfsrustfs
1.0.0:alpha70
rustfsrustfs
1.0.0:alpha71
rustfsrustfs
1.0.0:alpha72
rustfsrustfs
1.0.0:alpha73
rustfsrustfs
1.0.0:alpha74
rustfsrustfs
1.0.0:alpha75
rustfsrustfs
1.0.0:alpha76
rustfsrustfs
1.0.0:alpha77
rustfsrustfs
1.0.0:alpha78
rustfsrustfs
1.0.0:alpha79
rustfsrustfs
1.0.0:alpha8
rustfsrustfs
1.0.0:alpha9
𝑥
= Vulnerable software versions