GPU VulnDB

Database/Control plane, storage & DevOps

MinIO: unsigned x-amz-copy-source on a presigned PUT URL turns one-object write into a read of any object

CVSS 7.1CVE-2026-97731Control plane, storage & DevOpscurated

Impact

MinIO never enumerates the x-amz-* headers that actually arrived, only the ones the client claims it signed, so an unsigned header is neither hashed into the canonical request nor rejected. Because the router dispatches CopyObject on the presence of x-amz-copy-source alone, whoever holds a presigned PUT URL for one object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object that signing key can read. In a GPU cluster where MinIO holds datasets, checkpoints and model artifacts, a narrow upload grant handed to a tenant job becomes read access to every bucket the issuing key can reach. AWS S3 rejects the equivalent request with 403.

Who can reach it

Anyone holding a presigned PUT URL - typically a tenant workload, a CI job, or an external uploader that was deliberately given the narrowest possible grant. No MinIO credentials of their own are needed.

What to do

No upstream fix for minio/minio: the GitHub repository was archived in April 2026, so treat this as mitigate-only there. The pgsty/silo fork fixed it in commit 1233254. Mitigations: stop issuing presigned PUT URLs signed by broadly-scoped keys, sign them with a key whose policy covers only the target object, and block or strip x-amz-copy-source at the proxy in front of MinIO for presigned requests. Plan a migration off the archived project.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.