Database/Control plane, storage & DevOps
MinIO (server-side encryption / replication): An authenticated tenant can inject SSE metadata through replication
Impact
An authenticated tenant can inject SSE metadata through replication headers, corrupting how objects are recorded as encrypted. The practical outcome is objects that cannot be decrypted afterwards - durable data loss on a replicated bucket, plus confusion about which objects are actually protected.
Who can reach it
Any authenticated MinIO user able to send replication-related headers to the S3 endpoint.
What to do
Upgrade to the fixed release from GHSA-3rh2-v3gr-35p9 and restart the cluster. Verify readability of objects written during the exposure window on SSE-enabled replicated buckets, and restrict replication header handling to your replication service account.
References
Related entries
- MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process isCVE-2026-39414 · MinIO (S3 Select)High
- RabbitMQ: super-stream binding-keys parsed before the permission check, one PUT kills the nodeCVE-2026-67408 · RabbitMQ (rabbitmq_stream_management super-stream binding-keys handler)High
- Jenkins Ivy Report Plugin: XXE in Ivy report parsing gives an authenticated user file read on the controllerCVE-2026-70448 · Jenkins Ivy Report Plugin (XML parser for Ivy report files)High
- Determined AI (master API, generic task kill/pause/unpause handlers): The generic task kill, pause and unpauseCVE-2026-75109 · Determined AI (master API, generic task kill/pause/unpause handlers)High
- Jenkins ThinBackup plugin: attacker redirects backups and pulls arbitrary controller files into themCVE-2026-84667 · Jenkins ThinBackup plugin (backup configuration writable via Stapler data binding)High
- Linux kernel nfsd: stale opcnt after compound release leaks adjacent slab memory through the RPC status netlink dumpCVE-2026-89691 · Linux kernel nfsd (nfsd4_release_compoundargs, RPC status netlink interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.