CVE-2026-54330

Publication date 28 August 2026

Last updated 5 October 2026


Ubuntu priority

Cvss 3 Severity Score

8.1 · High

Score breakdown

Description

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.

Status

Package Ubuntu Release Status
ceph 26.04 LTS resolute
Fixed 20.2.0-0ubuntu2.1
24.04 LTS noble
Vulnerable, work in progress
22.04 LTS jammy
Fixed 17.2.9-0ubuntu0.22.04.4
20.04 LTS focal
Fixed 15.2.17-0ubuntu0.20.04.6+esm2
18.04 LTS bionic
Fixed 12.2.13-0ubuntu0.18.04.11+esm3
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.1 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities