Skip to content
MinIOGHSA-xh8f-g2qw-gcm7

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

Medium4.9CVE-2026-42600 · Published May 5, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/minio/minio
Go
>= 0.0.0-20220724015452, < 0.0.0-202604142132450.0.0-20260414213245
Details and references

### Impact _What kind of vulnerability is it? Who is impacted?_ A path traversal vulnerability in MinIO's `ReadMultiple` internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. Distributed-erasure (multi-node) MinIO deployments are impacted. Single-node standalone deployments do not register the route and are not affected. The attack requires an HS512 JWT signed with `MINIO_ROOT_PASSWORD` and carrying `accessKey = MINIO_ROOT_USER` , the same secret every peer in the cluster holds to authenticate internode traffic, so a compromised peer or any actor in possession of the root credential can mint one. The `ReadMultiple` handler (`cmd/storage-rest-server.go`) decodes a msgpack `ReadMultipleReq` body containing `Bucket`, `Prefix`, and `Files` fields and forwards them to `xlStorage.ReadMultiple` (`cmd/xl-storage.go`) without validation: ```go volumeDir := pathJoin(s.drivePath, req.Bucket) // traversal resolves here for _, f := range req.Files { fullPath := pathJoin(volumeDir, req.Prefix, f) data, mt, err = s.readAllDataWithDMTime(ctx, req.Bucket, volumeDir, fullPath) } ``` `pathJoin` calls `path.Clean`, which resolves `..` components and produces an absolute path anywhere on the filesystem , it is not a root jail. The global `setRequestValidityMiddleware` rejects `..` in `r.URL.Path` and `r.Form` but does not inspect request bodies, so msgpack-encoded traversal bypasses it. Sibling storage methods (`StatInfoFile`, `ReadFileHandler`, `ReadVersion`) validate their volume argument through `s.getVolDir(volume)`, which rejects `..`; `ReadMultiple` skips this call. The attacker sends `POST /minio/storage/{drivePath}/v63/rmpl` with a msgpack-encoded body carrying `../` sequences in the `Bucket` field. The server opens the resulting path via `os.OpenFile` with `O_RDONLY|O_NOATIME` and returns its contents in the msgpack response stream. **Impact by deployment:** - **Bare-metal with `User=minio` in the systemd unit** , the `O_NOATIME` ownership check bounds the read to files owned by the MinIO UID. Reachable secrets include TLS private keys, KMS/KES key material, systemd credentials, and data belonging to other tenants sharing the same UID on the host. Secrets leaked this way persist across cluster credential rotation. - **Containerized running as UID 0** (the historical default for the official Docker image, `docker-compose` examples, and Helm charts without `securityContext.runAsNonRoot`) , the primitive escalates to arbitrary host-filesystem disclosure: `/etc/shadow`, `/root/**`, Kubernetes service-account tokens, cloud-init metadata caches. **Affected components:** `cmd/storage-rest-server.go` (`ReadMultiple` handler), `cmd/xl-storage.go` (`xlStorage.ReadMultiple`). **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory , 'Path Traversal') **CVSS v4.0 Score:** 6.9 (Medium) **Vector:** `CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N` ### Affected Versions All MinIO releases from `RELEASE.2022-07-24T01-54-52Z` through the final release of the minio/minio open-source project, `RELEASE.2025-09-07T16-13-09Z`. The vulnerability was introduced in commit [`f939d1c18`](https://github.com/minio/minio/commit/f939d1c1831c71f4b1c14df6d9cd62b12ccce7a3) ("Independent Multipart Uploads", [PR #15346](https://github.com/minio/minio/pull/15346)), which added the `ReadMultiple` storage-REST endpoint as part of the multipart upload redesign. The first affected release is `RELEASE.2022-07-24T01-54-52Z`. ### Patches **Fixed in**: MinIO AIStor `RELEASE.2026-04-14T21-32-45Z` (recommended upgrade target). The fix , which removed the `ReadMultiple` handler, the corresponding storage-driver method, the msgpack datatypes, the REST-client wrapper, and the route registration , first shipped in **MinIO AIStor `RELEASE.2024-10-23T19-38-07Z`**. Every AIStor rele

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
BIT-minio-2026-42600, CVE-2026-42600, GO-2026-5757

More MinIO advisories

All MinIO
DateAdvisory
Apr 14MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
CVE-2026-41145High8.2no fix yet
Apr 14MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads
CVE-2026-40344High8.2no fix yet
Apr 9MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVE-2026-39414Highno fix yet
Mar 27MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
CVE-2026-34204High7.1no fix yet
Mar 20MinIO LDAP login brute-force via user enumeration and missing rate limit
CVE-2026-33419Criticalno fix yet
Mar 19MinIO has JWT Algorithm Confusion in OIDC Authentication
CVE-2026-33322Criticalno fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.