Threat Advisory

SeaweedFS Unauthenticated SSRF with Response Read-Back via VolumeServer.FetchAndWriteNeedle

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-73080 is a critical vulnerability affecting seaweedfs versions < 0.0.0-20260512171120-69da20bdaec9 that allows unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle. Versions prior to 4.24 are affected, as FetchAndWriteNeedle performed no authentication and no validation of the target before this patch. This flaw type enables anyone able to reach a volume server's gRPC port to coerce the server into issuing requests to arbitrary hosts and read the response back, disclosing instance metadata and IAM credentials on cloud deployments. The vulnerability is exploited via the environment template management API, requiring no credentials due to an unauthenticated default deployment. Configuring JWT signing keys does not close it, as that hardening does not apply to this RPC. Restricting volume server gRPC ports to trusted hosts or enabling mTLS mitigates the attack. This issue has significant business impact, as it can be used to reach otherwise-unexposed internal services and is a serious security concern for organizations utilizing SeaweedFS.

RECOMMENDATION:

We recommend you to update SeaweedFS to version 0.0.0-20260512171120-69da20bdaec9.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-73080 is a critical vulnerability affecting seaweedfs versions < 0.0.0-20260512171120-69da20bdaec9 that allows unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle. Versions prior to 4.24 are affected, as FetchAndWriteNeedle performed no authentication and no validation of the target before this patch. This flaw type enables anyone able to reach a volume server's gRPC port to coerce the server into issuing requests to arbitrary hosts and read the response back, disclosing instance metadata and IAM credentials on cloud deployments. The vulnerability is exploited via the environment template management API, requiring no credentials due to an unauthenticated default deployment. Configuring JWT signing keys does not close it, as that hardening does not apply to this RPC. Restricting volume server gRPC ports to trusted hosts or enabling mTLS mitigates the attack. This issue has significant business impact, as it can be used to reach otherwise-unexposed internal services and is a serious security concern for organizations utilizing SeaweedFS.

RECOMMENDATION:

We recommend you to update SeaweedFS to version 0.0.0-20260512171120-69da20bdaec9.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu