Junglewise Threat Intelligence

CVE-2026-34204: MinIO metadata injection in extractMetadataFromMime

CVE-2026-34204 · Severity: high · CVSS 7.1 · Published 2026-03-31

Technologies: Minio, github.com/minio/minio (Go). Vendors: MinIO, Go.

Executive brief

MinIO is a high-performance object storage system used to store and manage large amounts of data. A security flaw allows any user with basic upload permissions to inject fake encryption settings into files, making those files permanently unreadable. This can lead to a targeted denial-of-service where an attacker destroys the accessibility of data within the storage system.

Technical details

A flaw exists in the extractMetadataFromMime() function within cmd/handler-utils.go. The server unconditionally maps X-Minio-Replication-* headers to internal X-Minio-Internal-* encryption metadata without verifying if the request is a legitimate replication request (missing X-Minio-Source-Replication-Request header). An authenticated attacker with s3:PutObject permissions can send crafted replication headers during a standard upload. This causes the server to treat the object as encrypted with non-existent keys, resulting in permanent data loss for that object as subsequent GetObject or HeadObject calls will fail. The issue is patched in version RELEASE.2026-03-26T21-24-40Z.

Affected products

  • MinIO MinIO RELEASE.2024-03-30T09-41-56Z to RELEASE.2026-03-26T21-24-40Z

Timeline

  • 2024-03-28: other: Vulnerability introduced in commit 468a9fae8
  • 2026-03-27: advisory: GitHub advisory GHSA-3rh2-v3gr-35p9 published
  • 2026-03-26: patched: Fixed in RELEASE.2026-03-26T21-24-40Z
  • 2026-03-31: disclosed: CVE-2026-34204 published to NVD

References

Related threats