Loading
RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable client can spoof aws:SourceIp and satisfy IP-allowlist policies. This issue has been patched in version alpha.78.
Use CWE-290, Rustfs vendor hub and Rustfs product page to widen CVE-2026-21862 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-68926, CVE-2026-27822 and CVE-2025-68705 for nearby disclosures in the same product family.