{"schema_version":"1.7.3","id":"GHSA-f2ph-gc9m-q55f","published":"2026-01-15T21:14:55Z","modified":"2026-02-03T03:17:23.428241Z","aliases":["CVE-2025-68671","GO-2026-4321"],"summary":"lakeFS is Missing Timestamp Validation in S3 Gateway Authentication","details":"### Impact\nLakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. An attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire.\n\n### Patches\nThis issue affects all versions of lakeFS up to and including v1.74.4.\n\nThe vulnerability has been fixed in version v1.75.0.\n\nUsers should upgrade to version v1.75.0.\n\n### Workarounds\n\nUntil upgraded, implement these mitigations:\n\n- **Use short-lived credentials** - Rotate access keys frequently and **deactivate old keys**. For regular requests, captured requests only work until rotation. For presigned URLs, they remain valid until the credentials used to create them are deactivated.\n- **Network controls** - Restrict S3 gateway access to trusted networks/IPs to limit where replay attacks can originate.\n\nNote: These workarounds reduce risk but do not fully eliminate the vulnerability.\n\n### References\n- Original issue: https://github.com/treeverse/lakeFS/issues/9599\n- AWS Signature V4 Documentation: https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html\n- AWS Signature V4 S3 Requests: https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html\n- AWS Signature V2 Documentation: https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-header-based-auth.html","affected":[{"package":{"name":"github.com/treeverse/lakefs","ecosystem":"Go","purl":"pkg:golang/github.com/treeverse/lakefs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.75.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-f2ph-gc9m-q55f/GHSA-f2ph-gc9m-q55f.json"}}],"references":[{"type":"WEB","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-f2ph-gc9m-q55f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68671"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/issues/9599"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/pull/9710"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/commit/92966ae611d7f1a2bbe7fd56f9568c975aab2bd8"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"}],"database_specific":{"cwe_ids":["CWE-294"],"github_reviewed":true,"github_reviewed_at":"2026-01-15T21:14:55Z","nvd_published_at":"2026-01-15T23:15:49Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}