VDB

CVE-2025-68671

CVE-2025-68671 PUBLISHED CVSS 6.5 MEDIUM

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

EPSS 0.02% · 4.9th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.02%
4.9th percentile

Affected Products

VendorProductVersions
lakefslakefs0
treeverselakeFS< 1.75.0
github.comtreeverse/lakefs0

Timeline

  • Jan 15, 2026 CVE Published
  • Jan 16, 2026 CVE Updated
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 24, 2026 EPSS Score
  • Jan 24, 2026 PoC Published
  • Jan 24, 2026 PoC Published
  • Jan 24, 2026 PoC Published
  • Jan 27, 2026 EPSS Score
  • Jan 30, 2026 EPSS Score
  • Feb 2, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›