PT-2026-3139 · Lakefs · Lakefs

Published

2026-01-15

·

Updated

2026-01-26

·

CVE-2025-68671

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions lakeFS versions prior to 1.75.0
Description lakeFS's S3 gateway does not validate timestamps in authenticated requests, which allows for replay attacks. An attacker capturing a valid signed request can replay it until credentials are rotated, even after the request's intended expiration. The API endpoints are susceptible to this issue. The vulnerable parameters include those used in authenticated requests.
Recommendations Upgrade to version 1.75.0. Use short-lived credentials and rotate access keys frequently, deactivating old keys. Restrict S3 gateway access to trusted networks/IPs.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-68671
GHSA-F2PH-GC9M-Q55F
GO-2026-4321
SUSE-SU-2026:0292-1

Affected Products

Lakefs