Database/Control plane, storage & DevOps
MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowing
Impact
Signature validation on unsigned-trailer uploads is incomplete, so knowing only an access key ID - not the secret - is enough to write objects as that identity. Any tenant whose access key ID is visible in logs or config can be impersonated for writes.
Who can reach it
Any network client that can reach the S3 endpoint and has seen an access key ID.
What to do
Upgrade to MinIO RELEASE.2025-04-03T14-56-28Z or later and restart the cluster. Treat access key IDs as semi-sensitive going forward, and audit writes on shared buckets over the exposure window.
References
Related entries
- MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is notCVE-2026-41145 · MinIO (S3 API, unsigned-trailer uploads)High
- HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsCVE-2025-37101 · HPE OneView for VMware vCenter (vertical privilege escalation)High
- F5 BIG-IP (iHealth command / tmsh restricted shell): An authenticated attacker with at least a resource-administratorCVE-2025-61958 · F5 BIG-IP (iHealth command / tmsh restricted shell)High
- GitLab CE/EE: stored XSS in analytics dashboard pagination controlsCVE-2026-15216 · GitLab CE/EE (analytics dashboard pagination controls)High
- GitLab CE/EE: stored XSS in analytics dashboard table cell renderingCVE-2026-15217 · GitLab CE/EE (analytics dashboard table cell rendering)High
- Sigstore Fulcio: OIDC discovery follows cross-host redirects and leaks ServiceAccount tokensCVE-2026-49478 · Sigstore Fulcio (OIDC discovery HTTP client, cross-host redirects)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.