Database/Control plane, storage & DevOps
MinIO: unsigned x-amz-copy-source on a presigned PUT URL turns one-object write into a read of any object
Impact
MinIO never enumerates the x-amz-* headers that actually arrived, only the ones the client claims it signed, so an unsigned header is neither hashed into the canonical request nor rejected. Because the router dispatches CopyObject on the presence of x-amz-copy-source alone, whoever holds a presigned PUT URL for one object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object that signing key can read. In a GPU cluster where MinIO holds datasets, checkpoints and model artifacts, a narrow upload grant handed to a tenant job becomes read access to every bucket the issuing key can reach. AWS S3 rejects the equivalent request with 403.
Who can reach it
Anyone holding a presigned PUT URL - typically a tenant workload, a CI job, or an external uploader that was deliberately given the narrowest possible grant. No MinIO credentials of their own are needed.
What to do
No upstream fix for minio/minio: the GitHub repository was archived in April 2026, so treat this as mitigate-only there. The pgsty/silo fork fixed it in commit 1233254. Mitigations: stop issuing presigned PUT URLs signed by broadly-scoped keys, sign them with a key whose policy covers only the target object, and block or strip x-amz-copy-source at the proxy in front of MinIO for presigned requests. Plan a migration off the archived project.
References
Related entries
- Flux CD (allow-webhooks NetworkPolicy, notification-controller event server): CROSS-TENANT EVENT FORGERY: theNCVD-2026-057-flux-cd-allow-webhooks-networkpo · Flux CD (allow-webhooks NetworkPolicy, notification-controller event server)High
- OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bitCVE-2023-51767 · OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bit…High
- AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool doesCVE-2024-36334 · AMD Radeon RGB tool - signature verification on files in the installation directoryHigh
- Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachableCVE-2024-39766 · Intel Neural Compressor (SQL injection, second instance)High
- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsCVE-2025-32023 · RedisHigh
- Sidero Omni: SAML assertion replay race lets a captured saml-session token be redeemed more than onceCVE-2026-45720 · Sidero Omni (SAML session interceptor, internal/pkg/auth/interceptor/saml.go)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.