criticalCVSS 9.3Vulnerability

CVE-2026-73080

### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing requests to arbitrary hosts — including loopback, link-local, RFC 1918, and cloud metadata endpoints such as `169.254.169.254` — and read the response back. On cloud deployments this discloses instance metadata and IAM credentials, and can be used to reach otherwise-unexposed internal services (SSRF with response read-back). The volume server gRPC plane is unauthenticated on a default deployment, so no credentials are required. Configuring the documented JWT signing keys does not close it, because that hardening does not apply to this RPC. ### Affected component - `weed/server/volume_grpc_remote.go` (`FetchAndWriteNeedle`) - `weed/remote_storage/s3/s3_storage_client.go` ### Patches Fixed in **4.24**. `FetchAndWriteNeedle` now requires admin authorization and refuses loopback / link-local / RFC 1918 / IMDS destinations through a guarded dialer that resolves the host itself and pins the resolved address for the duration of the request, defeating DNS-rebinding. The Rust volume server carries the equivalent endpoint validation. ### Workarounds Restrict volume server gRPC ports to trusted hosts via firewall / network policy, and enable mTLS via `security.toml`.

Properties

ghsa_id
GHSA-87fv-vqqr-m4jr
severity
critical
summary
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
cvss_score
9.3
cve_id
CVE-2026-73080
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-08-11T15:58:23Z
source_url
https://github.com/advisories/GHSA-87fv-vqqr-m4jr
ghsa_updated
2026-08-11T15:58:24Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/seaweedfs/seaweedfs

AFFECTS (1)

[Software]go/github.com/seaweedfs/seaweedfs

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73080 (CVSS 9.3) — Ninja Signal Threat Intelligence | Ninja Signal