CVE-2026-73080
SeaweedFS unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
- Severity
- critical
- Affected product
- SeaweedFS
- Affected versions
- SeaweedFS < 4.24
- Fixed in
- SeaweedFS 4.24
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints SeaweedFS from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23 with the SeaweedFS fingerprint pair (master body row + volume Server-header row, measured against 4.44 on loopback - the patched side, consistent with GHSA-87fv-vqqr-m4jr fixing 4.24). ALL versions prior to 4.24 are affected per the GHSA, hence a single lt with no lower bound; 4.24 makes FetchAndWriteNeedle require admin authorization and refuse loopback addresses. Version-match only, NOT a probe: the vector is the volume server's gRPC port, a surface this scanner does not speak - the fingerprint numbers the deployment, the advisory is the claim, and the master/volume HTTP surfaces being unauthenticated by default (measured) is what makes reaching the gRPC port plausible from the same host.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →