The Ceph project released Ceph 20.2.4 and Ceph 19.2.6 to fix four security vulnerabilities affecting CephX, the Ceph Monitor config-key store, and RADOS Gateway (RGW) handling of SigV4 requests and STS session tokens. The most serious issue, CVE-2025-30156, is an authentication bypass in CephX caused by unauthenticated AES-128-CBC encryption with a hard-coded initialization vector and no HMAC, allowing ticket tampering and credential forgery under certain conditions. Other fixes address unauthorized disclosure of sensitive secrets, including OSD LUKS passphrases and cephadm SSH private keys, as well as privilege escalation that can reach full RGW administrator access.
The flaws also affect OpenStack deployments that rely on Ceph keyrings, including Nova, Cinder, Glance, and Manila, and can expose tenants using native CephFS through Manila. OpenStack and Ceph advisories say versions prior to 20.2.4 and 19.2.6 are vulnerable and urge operators to upgrade Ceph servers and clients, rotate all CephX credentials to the new aes256k key type, and restart or live migrate Nova guests so they load updated keys. Ceph said it replaced the insecure CephX cryptography with AES-256-CTS-HMAC-SHA384-192 and recommends enforcing the new cipher once key rotation is complete.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 19, 2026, the Ceph project released Ceph Tentacle 20.2.4 and Ceph Squid 19.2.6 to fix four vulnerabilities affecting CephX, the Monitor config-key store, and RGW components. The release addressed CVE-2025-30156, CVE-2026-39944, CVE-2026-50152, and CVE-2026-54330, including replacing insecure CephX AES-CBC usage with AES-256-CTS-HMAC-SHA384-192.
An OpenStack security notice warned that multiple Ceph authentication vulnerabilities affect OpenStack deployments using CephX keyrings, including Nova, Cinder, Glance, and Manila. The notice advised upgrading to patched Ceph releases, rotating CephX credentials to the new aes256k key type, and restarting or live migrating Nova guests so they load new keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
explore.alas.aws.amazon.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.