Executive brief
MinIO is a high-performance object storage system used to store and manage large amounts of data. A security flaw allows any user with basic upload permissions to inject fake encryption settings into files, making those files permanently unreadable. This can lead to a targeted denial-of-service where an attacker destroys the accessibility of data within the storage system.
Technical details
A flaw exists in the extractMetadataFromMime() function within cmd/handler-utils.go. The server unconditionally maps X-Minio-Replication-* headers to internal X-Minio-Internal-* encryption metadata without verifying if the request is a legitimate replication request (missing X-Minio-Source-Replication-Request header). An authenticated attacker with s3:PutObject permissions can send crafted replication headers during a standard upload. This causes the server to treat the object as encrypted with non-existent keys, resulting in permanent data loss for that object as subsequent GetObject or HeadObject calls will fail. The issue is patched in version RELEASE.2026-03-26T21-24-40Z.
Affected products
- MinIO MinIO RELEASE.2024-03-30T09-41-56Z to RELEASE.2026-03-26T21-24-40Z
Timeline
- 2024-03-28: other: Vulnerability introduced in commit 468a9fae8
- 2026-03-27: advisory: GitHub advisory GHSA-3rh2-v3gr-35p9 published
- 2026-03-26: patched: Fixed in RELEASE.2026-03-26T21-24-40Z
- 2026-03-31: disclosed: CVE-2026-34204 published to NVD