> USN-8867-1: Ceph vulnerability
[DATE: 05/10/2026 11:31]
[LANGUAGE: EN]
It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not
reject requests carrying x-amz-* headers that were absent from the signed
header set. An attacker holding a presigned URL could possibly use this issue to
attach arbitrary unsigned x-amz-* headers that RGW would honor, allowing them to escalate
their privileges beyond what the URL's signer intended.