{"id":"GHSA-gw2x-q739-qhcr","summary":"RustFS gRPC GetMetrics deserialization panic enables remote DoS","details":"### Summary\nA malformed gRPC `GetMetrics` request causes `get_metrics` to `unwrap()` failed deserialization of `metric_type`/`opts`, panicking the handler thread and enabling remote denial of service of the metrics endpoint.\n\n### Details\n- Vulnerable code: `rustfs/src/storage/tonic_service.rs:1775-1782`:\n  - `MetricType` and `CollectMetricsOpts` are deserialized with `Deserialize::deserialize(...).unwrap()` from client-supplied bytes.\n  - Malformed `metric_type`/`opts` (e.g., empty or truncated rmp-serde payloads) trigger `InvalidMarkerRead` and panic.\n- Reachability: same TCP listener as S3 (default `:9000`); only a static interceptor token `authorization: rustfs rpc` is checked in `server/http.rs:677`.\n- Impact scope: panic terminates the worker handling the request, causing metrics service interruption and potential process instability.\n\n### PoC\n\n[rustfs-grpc-metrics-invalid-metric-type-panic-poc.tar.gz](https://github.com/user-attachments/files/24038341/rustfs-grpc-metrics-invalid-metric-type-panic-poc.tar.gz)\n\n\n1) Start RustFS (example local dev):\n```bash\nmkdir -p /tmp/rustfs-data1 /tmp/rustfs-data2\nRUSTFS_ACCESS_KEY=devadmin RUSTFS_SECRET_KEY=devadmin \\\n  cargo run --bin rustfs -- --address 0.0.0.0:9000 \\\n  /tmp/rustfs-data1 /tmp/rustfs-data2\n```\n2) From `rustfs-grpc-metrics-invalid-metric-type-panic-poc/`, run:\n```bash\nENDPOINT=127.0.0.1:9000 make run\n# or: grpcurl -plaintext \\\n#   -H 'authorization: rustfs rpc' \\\n#   -import-path ../crates/protos/src -proto node.proto \\\n#   -d '{\"metric_type\":\"\",\"opts\":\"\"}' \\\n#   127.0.0.1:9000 node_service.NodeService/GetMetrics\n```\n3) Observe panic in server logs at `tonic_service.rs:get_metrics` with `InvalidMarkerRead` and worker crash; client output saved to `poc-response.txt`/`poc-grpcurl.log`.\n\n### Impact\n- Vulnerability type: remote unauthenticated (static token) denial of service via panic in gRPC handler.\n- Who is impacted: any deployment exposing the gRPC endpoint where an attacker can reach port 9000 and supply the known `authorization: rustfs rpc` header; metrics service is disrupted and may affect overall stability depending on runtime crash handling.","aliases":["CVE-2025-69255"],"modified":"2026-02-03T03:16:17.069042Z","published":"2026-01-07T18:36:23Z","database_specific":{"cwe_ids":["CWE-755"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-01-07T18:36:23Z","nvd_published_at":"2026-01-07T21:16:00Z"},"references":[{"type":"WEB","url":"https://github.com/rustfs/rustfs/security/advisories/GHSA-gw2x-q739-qhcr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69255"},{"type":"WEB","url":"https://github.com/rustfs/rustfs/commit/eb33e82b56ed11fd12bb39416359d8d60737dc7a"},{"type":"PACKAGE","url":"https://github.com/rustfs/rustfs"}],"affected":[{"package":{"name":"rustfs","ecosystem":"crates.io","purl":"pkg:cargo/rustfs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0-alpha.13"},{"fixed":"1.0.0-alpha.78"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.0-alpha.77","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-gw2x-q739-qhcr/GHSA-gw2x-q739-qhcr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}