GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (SFTP gateway): The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate as

CVE-2025-27414Control plane, storage & DevOpscurated

Impact

The SFTP frontend trusts an SSH public key it should not, letting an attacker authenticate as another user without that user's private key. Whatever buckets that identity can reach are now readable and writable by the attacker over SFTP.

Who can reach it

Any client that can reach the MinIO SFTP port on a deployment with SFTP enabled and public-key auth configured.

What to do

Upgrade to the release named in GHSA-wc79-7x8x-2p58 and restart the SFTP listener. If SFTP is not a requirement, disable it entirely - it is a second authentication surface on the same data.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.