Replay Attack Affecting github.com/treeverse/lakefs/pkg/gateway/sig package, versions <1.74.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMTREEVERSELAKEFSPKGGATEWAYSIG-15032893
  • published18 Jan 2026
  • disclosed15 Jan 2026
  • creditUnknown

Introduced: 15 Jan 2026

CVE-2025-68671  (opens in a new tab)
CWE-294  (opens in a new tab)

How to fix?

Upgrade github.com/treeverse/lakefs/pkg/gateway/sig to version 1.74.0 or higher.

Overview

Affected versions of this package are vulnerable to Replay Attack via the authentication process in the S3 gateway. An attacker can gain unauthorized access or perform actions by replaying previously captured signed requests, as the system does not validate timestamps on authenticated requests.

Note: This allows repeated use of valid requests until credentials are rotated or deactivated.

Workaround

This vulnerability can be mitigated by using short-lived credentials, rotating access keys frequently, deactivating old keys, and restricting S3 gateway access to trusted networks or IPs.

CVSS Base Scores

version 4.0
version 3.1