CVE-2026-58372 – SeaweedFS < 4.34 – Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
CVE ID :CVE-2026-58372 Published : June 30, 2026, 3:57 p.m. | 2 hours, 18 minutes ago Description :SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket…
