๐Ÿ” CVE Alert

CVE-2026-34204

UNKNOWN 0.0

MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z.

CWE CWE-287
Vendor minio
Product minio
Published Mar 31, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for minio minio

Be the first to know when new unknown vulnerabilities affecting minio minio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

minio / minio
< RELEASE.2026-03-26T21-24-40Z

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/minio/minio/security/advisories/GHSA-3rh2-v3gr-35p9