MinIO security advisories
15 advisories · 7 critical or high in 12 months · latest May 5
15 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 5 | MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint CVE-2026-42600Medium4.9fixed in 0.0.0-20260414213245 | Medium4.9 | 0.0.0-20260414213245 |
| Apr 14 | MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads CVE-2026-41145High8.2no fix yet | High8.2 | No fix yet |
| Apr 14 | MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads CVE-2026-40344High8.2no fix yet | High8.2 | No fix yet |
| Apr 9 | MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing CVE-2026-39414Highno fix yet | High | No fix yet |
| Mar 27 | MinIO is Vulnerable to SSE Metadata Injection via Replication Headers CVE-2026-34204High7.1no fix yet | High7.1 | No fix yet |
| Mar 20 | MinIO LDAP login brute-force via user enumeration and missing rate limit CVE-2026-33419Criticalno fix yet | Critical | No fix yet |
| Mar 19 | MinIO has JWT Algorithm Confusion in OIDC Authentication CVE-2026-33322Criticalno fix yet | Critical | No fix yet |
| Oct 162025 | MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS CVE-2025-62506High8.1fixed in 0.0.0-20251015170045-c1a49490c78e | High8.1 | 0.0.0-20251015170045-c1a49490c78e |
| Apr 42025 | MinIO performs incomplete signature validation for unsigned-trailer uploads CVE-2025-31489Highfixed in 0.0.0-20250403145552-8c70975283f9 | High | 0.0.0-20250403145552-8c70975283f9 |
| Mar 32025 | MinIO allows an SFTP authentication bypass due to improperly trusted SSH key CVE-2025-27414Mediumfixed in 0.0.0-20250227184332-4c71f1b4ec0f | Medium | 0.0.0-20250227184332-4c71f1b4ec0f |
| Dec 162024 | MinIO vulnerable to privilege escalation in IAM import API CVE-2024-55949Highfixed in 0.0.0-20241213221912-68b004a48f41 | High | 0.0.0-20241213221912-68b004a48f41 |
| May 292024 | MinIO information disclosure vulnerability CVE-2024-36107Medium5.3fixed in 0.0.0-20240527191746-e0fe7cc39172 | Medium5.3 | 0.0.0-20240527191746-e0fe7cc39172 |
| Feb 12024 | Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation CVE-2024-24747High8.8fixed in 0.0.0-20240131185645-0ae4915a9391 | High8.8 | 0.0.0-20240131185645-0ae4915a9391 |
| Sep 62023 | Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation CVE-2023-28433High8.8fixed in 0.0.0-202303200735 | High8.8 | 0.0.0-202303200735 |
| Sep 52023 | Privilege Escalation on Linux/MacOS CVE-2023-28434High8.8fixed in 0.0.0-202303200415 | High8.8 | 0.0.0-202303200415 |
About MinIO
S3-compatible object storage for AI data.
Packages watched: github.com/minio/minio (Go).
MinIO elsewhere on fru.dev: Repos