criticalCVSS 9.8Vulnerability

CVE-2026-88018

### Summary `rclone serve s3`'s handler chain, when `--auth-proxy` is configured, is (outermost first): `authPairMiddleware` -> `proxyAuthMiddleware` -> gofakes3's own SigV4-verifying handler. `authPairMiddleware` parses the accessKeyID straight out of the incoming request's own `Authorization` header (entirely client-controlled) and registers `{accessKey: ws.s3Secret}` into gofakes3's shared credential store via `AddAuthKeys`, for EVERY access key any client presents - not just ones previously known to the server. `ws.s3Secret` defaults to `""` whenever `--auth-key` is not set, which the `--auth-proxy` documentation (and the reference `bin/test_proxy.py`) presents as a complete, standalone authentication mechanism requiring no other flag - matching how it's used for `serve webdav`/`ftp`/`sftp`. gofakes3's SigV4 verification then checks the request's signature against exactly the secret `authPairMiddleware` just registered for that same client-chosen key. An empty string is a valid HMAC key, so a caller can trivially compute a correct SigV4 signature for ANY access key ID of their choosing using an empty secret, and verification passes. Crucially, the auth-proxy script never receives a real secret to verify against, for S3 specifically: `Server.auth()` calls `w.proxy.Call(md5(accessKeyID), accessKeyID, false, r.RemoteAddr)` - passing the access key ID itself as BOTH the hashed "user" and the raw "auth"/password fields. Contrast with `serve webdav`/`ftp`/`sftp`, whose proxy integration passes the client's actual typed password (see `bin/test_proxy.py`, which forwards it into a backing SFTP login for real verification). For S3, no independent secret is ever transmitted to the proxy script at all, so no script - however carefully written - can distinguish a legitimate holder of an access key ID from an attacker who merely picked the same string. Net effect: with `--auth-proxy` configured and `--auth-key` not also set (the configuration the feature is documented to

Properties

ghsa_id
GHSA-xwwr-4h3p-r22c
severity
critical
summary
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
cvss_score
9.8
cve_id
CVE-2026-88018
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-09-10T22:49:07Z
source_url
https://github.com/advisories/GHSA-xwwr-4h3p-r22c
ghsa_updated
2026-09-10T22:49:08Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]go/github.com/rclone/rclone

AFFECTS (1)

[Software]go/github.com/rclone/rclone

HAS_WEAKNESS (2)

[Weakness]Improper Authentication
[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88018 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal