Source: notice USN-8867-1 from the Ubuntu Security feed, published on October 5, 2026, according to the received text, which is an automatic translation. The issue is in the SigV4 handler of the Ceph Object Gateway (RGW). It did not reject requests containing x-amz-* headers missing from the set of signed headers. According to the description, an attacker holding a pre-signed URL could possibly attach arbitrary unsigned x-amz-* headers, which RGW would accept, raising privileges beyond what the signer intended. The received text does not state affected versions or the fixed version; check the original notice on the Ubuntu website to verify these details. Relevance: Rota Nacional does not run Ceph and does not offer object storage built on this component, so this flaw is neither a platform feature nor a platform fix. For teams operating Ceph, the general recommendation is to review the notice, apply the update indicated by the distribution vendor, and audit the validity and scope of pre-signed URLs in use. Pre-signed URLs work as temporary credentials and should be treated as secrets, including when they circulate in chats, tickets or AI prompts.
Cyber ·
USN-8867-1: unsigned x-amz-* headers in Ceph RGW
Ubuntu Security feed notice on the Ceph Object Gateway: the SigV4 handler could accept x-amz-* headers outside the signed set, with a risk of privilege escalation through a pre-signed URL.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.