Silo Blog

Posts in 2026
  • SILO 20260618 Released

    June 18, 2026 in Release

    SILO 20260618 Released

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

    Read more

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

    Read more

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    June 12, 2026 in Security Chronicle

    CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Read more

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Read more

  • SILO 20260417 Released

    April 17, 2026 in Release

    SILO 20260417 Released

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

    Read more

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

    Read more

  • MinIO Fork, Promise Kept

    April 17, 2026 in Post

    MinIO Fork, Promise Kept

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. …

    Read more

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. …

    Read more

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    April 16, 2026 in Security Chronicle

    CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Read more

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Read more

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    April 16, 2026 in Security Chronicle

    CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature …

    Read more

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature …

    Read more

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    April 15, 2026 in Security Chronicle

    CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Read more

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Read more

  • CVE-2026-34204: Replication Metadata Injection

    April 15, 2026 in Security Chronicle

    CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Read more

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Read more

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    April 15, 2026 in Security Chronicle

    CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Read more

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Read more

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    April 15, 2026 in Security Chronicle

    CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Read more

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Read more