PT-2026-6208 · Rustfs · Rustfs

Cchheang

·

Published

2026-02-03

·

Updated

2026-02-24

·

CVE-2026-24762

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RustFS versions alpha.13 through alpha.81
Description RustFS logs sensitive credential material, including access key, secret key, and session token, to application logs at the INFO level. This results in credentials being recorded in plaintext in log output, potentially accessible to internal or external log consumers, which could lead to compromise of sensitive credentials. The server writes newly generated STS credential information to logs, as demonstrated in log excerpts. An attacker or unauthorized internal user with access to logs could retrieve these credentials and use them to authenticate to RustFS services or perform other unauthorized actions. This issue is classified as an information disclosure issue.
Recommendations RustFS versions alpha.13 through alpha.81: Upgrade to version alpha.82 or later to resolve this issue. Do not include secrets in log output—redact secret key, session token, and similar fields. Log only safe identifiers such as non-sensitive IDs.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24762
GHSA-R54G-49RX-98CR

Affected Products

Rustfs