rustfs
v0.0.2crates.io· RustRustFS is a high-performance distributed object storage software built using Rust, one of the most popular languages worldwide.
The verdict
Has 6 high-severity advisories. Verify a patched version exists before using. Check the OSV link for the fixed-in version.
Check the OSV link for the fixed-in version.
Live from the crates.io registry · derived rules, not AI
How it scores
MaintenanceAging
PopularityNiche
Security6 advisories
LicensePermissive
DepsZero deps
Maintenance
Last published 11 months ago — check before adopting.
Popularity
8 downloads / week
Security
6 known advisories (worst: high severity).
License
Apache-2.0
Dependencies
No runtime dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHRustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
- HIGHRustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
- HIGHRustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooksGHSA-pfcq-4gjr-6gjm Published 2026-04-22
- HIGHRust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
- MEDIUMRustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationGHSA-mx42-j6wv-px98 Published 2026-04-08
- MEDIUMRustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
Recent releases
- 0.0.211 months ago
- 0.0.111 months ago