CVE-2018-12088: s3ql Project s3ql

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.

Affected products

Published 2018-06-10. Last modified 2026-06-17.