It’s a CVE Kind of Day

by Sage McTaggart, Michael Hackett, and Federico Lucifredi
Messenger and MON
The IBM Ceph Security team is leading the response to a high-severity security vulnerability reported by an independent researcher, coordinating closely with the Ceph Community’s upstream security response process through Sage McTaggart, who is double-hatting both roles. The vulnerability’s impact is mitigated in most deployments because it requires access to an internal cluster network typically isolated from end-users. However, where such network access exists, an attacker could bypass access controls and forge privileged credentials (CVE-2025-30156 – AES-CBC misuse in CephX facilitating authentication bypass).
Erin Shepherd (E43.eu) was the original reporter, with independent reports from David Mohren (CLYSO) and David Korczynski (Ada Logics / Anthropic’s Project Glasswing).
We are taking this...









