๐Ÿ” CVE Alert

CVE-2026-97731

HIGH 7.1
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected.

CWE CWE-347
Vendor minio
Product minio
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for minio minio

Be the first to know when new high vulnerabilities affecting minio minio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

MinIO / MinIO
0 โ‰ค 7aac2a2c5b7c882e68c1ce017d8256be2feea27f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
silo.pgsty.com: https://silo.pgsty.com/about/security-advisories/#sn-2026-011 github.com: https://github.com/pgsty/silo/commit/1233254309b15571f101b2b26d531951ceaeef1e