<Vulnerability name="CVE-2026-54330">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-19T17:57:46</PublicDate>
    <Bugzilla id="2519428" url="https://bugzilla.redhat.com/show_bug.cgi?id=2519428" xml:lang="en:us">
ceph: ceph: RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.2</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-347</CWE>
    <Details xml:lang="en:us" source="Mitre">
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Ceph RGW's SigV4 signature verification handler. When processing S3 requests, RGW verifies only the headers explicitly listed in the X-Amz-SignedHeaders field but does not reject requests that carry additional unsigned x-amz-* headers. This diverges from the AWS S3 specification, which requires all x-amz-* headers to be signed. As a result, anyone holding a presigned PUT URL can attach arbitrary unsigned x-amz-* headers that RGW will honor, effectively escalating their privileges beyond what the original URL signer authorized. This can lead to unauthorized access to and modification of S3 objects.
    </Details>
    <Statement xml:lang="en:us">
The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that exploitation requires only a presigned PUT URL and knowledge of the SigV4 protocol gap. Successful exploitation allows an attacker to escalate privileges beyond the scope intended by the presigned URL signer, gaining unauthorized read and write access to S3 objects. The vulnerability's root cause is incomplete signature verification in RGW's SigV4 handler, which fails to reject requests containing unsigned x-amz-* headers.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:4">
        <ProductName>Red Hat Ceph Storage 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:5">
        <ProductName>Red Hat Ceph Storage 5</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:6">
        <ProductName>Red Hat Ceph Storage 6</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:7">
        <ProductName>Red Hat Ceph Storage 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:7">
        <ProductName>Red Hat Ceph Storage 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/rhceph-7-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:8">
        <ProductName>Red Hat Ceph Storage 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:8">
        <ProductName>Red Hat Ceph Storage 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/rhceph-8-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:9">
        <ProductName>Red Hat Ceph Storage 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>ceph</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:9">
        <ProductName>Red Hat Ceph Storage 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/rhceph-9-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-54330
https://nvd.nist.gov/vuln/detail/CVE-2026-54330
    </References>
</Vulnerability>