OSG-SEC-2026-08-27 Important-Ceph Vulnerabilities (CVE-2025-30156 and CVE-2026-54330)
Dear OSG Security Contacts,
Two Important vulnerabilities have been identified in Ceph (CVE-2025-30156 and CVE-2026-54330) [3] [4] affecting CephX authentication and the Ceph Object Gateway (RGW) S3 interface.
Successful exploitation could allow an attacker to gain unauthorized access to Ceph resources, including potentially gaining administrative control of a Ceph cluster or accessing and modifying S3 objects.
WHAT ARE THE VULNERABILITIES:
CVE-2025-30156 is a vulnerability in the CephX authentication protocol. An attacker who has obtained a low-privilege CephX entity key and has network access to a Ceph monitor may be able to forge credentials for more privileged Ceph entities. Successful exploitation could provide cluster-wide access, including the ability to read or modify stored data and gain administrative control over Ceph services.
CVE-2026-54330 affects signature verification in the Ceph Object Gateway (RGW) S3 interface. An attacker with access to a presigned PUT URL may be able to include unsigned x-amz-* headers that are accepted by RGW, allowing actions beyond those originally authorized by the URL. This could result in unauthorized access to or modification of S3 objects.
IMPACTED VERSIONS:
- The vulnerabilities affect Ceph releases containing the vulnerable CephX and RGW implementations.
- The Ceph project has addressed these vulnerabilities in Tentacle 20.2.4 [1] and in Squid 19.2.6 [2]. Sites should consult their Ceph or Linux distribution vendor to determine whether their installed packages are affected and whether updated packages are available.
- Red Hat currently lists affected Red Hat Ceph Storage releases with fixes deferred for several supported versions. Red Hat Ceph Storage 9 is listed as not affected by CVE-2025-30156, while CVE-2026-54330 affects Red Hat Ceph Storage releases currently evaluated by Red Hat.
MITIGATION
For CVE-2025-30156, sites unable to update immediately should restrict access to the Ceph messenger network and Ceph monitors, minimize the number of CephX credentials in circulation, and protect existing CephX keys from compromise.
Red Hat also recommends using Messenger v2 (msgr2) with on-wire encryption where possible.
Red Hat currently lists no practical mitigation for CVE-2026-54330 that meets its deployment and stability criteria.
WHAT YOU SHOULD DO:
- Sites running Ceph should determine whether their installed versions and deployed components are affected.
- Apply vendor-provided Ceph updates addressing these vulnerabilities as they become available. Sites running upstream Ceph should follow the Ceph upgrade guidance for an applicable fixed release, including Squid 19.2.6, Tentacle 20.2.4 or later.
- For CVE-2025-30156, restrict network access to Ceph monitors and review the handling and distribution of CephX credentials until updates can be applied.
- Sites using Ceph RGW/S3, particularly deployments that issue presigned URLs, should prioritize updates addressing CVE-2026-54330.
- Review the applicable Ceph release notes carefully before upgrading, as additional upgrade steps may be required.
REFERENCES
[1] https://docs.ceph.com/en/latest/releases/tentacle/#v20-2-4-tentacle
[2] https://docs.ceph.com/en/latest/releases/squid/
[3] https://access.redhat.com/security/cve/cve-2025-30156
[4] https://access.redhat.com/security/cve/cve-2026-54330
[5] https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released/
Please contact the OSG security team at [email protected] if you have any questions or concerns.
OSG Security Team