Skip to content

SILO Security Chronicle

This is the security chronicle of the SILO community fork, listed from newest to oldest. Records may cover a CVE, a SILO-local SN finding, several related repairs, or a non-vulnerability correctness audit: the original threat model, the turns taken during review, the rejected alternatives, the final invariant, the evidence, and the compatibility cost all stay with that incident.

The security ledger indexes identifiers, fixed source and first containing releases. An investigation date is not a release date, and publishing an article does not deliver a fix.

  • September Security Repairs: Payload Integrity, IAM Revocation and Console Sharing

    In Security

    SecuritySigV4IAMConsole

    Featured Image for September Security Repairs: Payload Integrity, IAM Revocation and Console Sharing

    This record covers three repairs and their delivery boundaries as of September 16. The identifiers are SILO-local advisory numbers, not CVEs or assigned CVSS scores. The security ledger is the maintained index. Finding Fixed source Published delivery …

    This record covers three repairs and their delivery boundaries as of September 16. The identifiers are SILO-local advisory numbers, not CVEs or assigned CVSS scores. The security ledger is the maintained index. Finding Fixed source Published delivery …

  • SN-2026-011: Fix and Release Status

    In Security

    Securitysilo

    Featured Image for SN-2026-011: Fix and Release Status

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

  • SILO 20260903 Security Notes: SN-2026-006 through 010

    In Security

    SecurityS3SSE-CReplicationIAM

    Featured Image for SILO 20260903 Security Notes: SN-2026-006 through 010

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

  • Three Headers, One Lie: Making the Client Source Address Mean Something

    In Security

    SecuritySource Address

    Featured Image for Three Headers, One Lie: Making the Client Source Address Mean Something

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    In Security

    SecurityVersion ID

    Featured Image for Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    In Security

    SecurityObject Grant

    Featured Image for Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

  • The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    In Security

    SecurityBucket Notifications

    Featured Image for The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    In Security

    SecurityMultipart Upload

    Featured Image for Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

  • Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    In Security

    SecurityPath Containment

    Featured Image for Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    In Security

    SecurityReadMultiple

    Featured Image for CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    In Security

    SecurityUnsigned Trailer

    Featured Image for CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    In Security

    SecuritySnowball

    Featured Image for CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    In Security

    SecurityS3 Select

    Featured Image for CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    SecurityReplication

    Featured Image for CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    In Security

    SecurityLDAP STS

    Featured Image for CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    In Security

    SecurityOIDC

    Featured Image for CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

  • CVE-2026-32285: The jsonparser Advisory That Required No Patch

    In Security

    Securityjsonparser

    Featured Image for CVE-2026-32285: The jsonparser Advisory That Required No Patch

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

  • CVE-2025-62506: Session-Policy Privilege Escalation

    In Security

    SecurityIAM

    Featured Image for CVE-2025-62506: Session-Policy Privilege Escalation

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …