Database/Control plane, storage & DevOps
Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authentication
Impact
The FlashBlade equivalent of the FlashArray pre-authentication denial of service: malformed authentication input stops the array serving data. For a fleet using FlashBlade as the shared training filesystem, that is a full stall.
Who can reach it
Network reach to the FlashBlade authentication surface, no credentials needed. Attack complexity is rated high, so it is not trivially repeatable, but it needs no account.
What to do
Upgrade Purity//FB to the fixed release in Pure's security bulletin, and restrict network exposure of the login endpoints in the meantime.
References
Related entries
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferCVE-2025-26336 · Dell Chassis Management Controller (PowerEdge FX2 / VRTX)High
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeCVE-2026-47866 · VMware Avi Load Balancer (Avi Controller control plane)High
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesCVE-2026-54100 · Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key)High
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceCVE-2026-63443 · Coder (workspace agent API client, agentConn.apiClient redirect handling)High
- Renovate: mutual-TLS private key written to logs in cleartext when it appears outside its own fieldCVE-2026-88883 · Renovate self-hosted (log redaction of hostRules[].httpsPrivateKey)High
- IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport): An attacker who can speak to the cluster'sCVE-2020-4927 · IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.