SN-2026-011: Fix and Release Status
Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with
123325430.
The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public
Server releases are affected. No new fixed Server release is established by
the pkg v3.14.0 or mcli 20260913 publication.
A holder of a signed PUT request could add an unsigned x-amz-copy-source
header and turn the permitted write into a copy of another object readable by
the signing key. A destination that permits anonymous reads can expose those
copied bytes. This affects both presigned and Authorization-header requests;
the holder does not need the signing credentials.
The patch checks the received x-amz-* headers against the signed-header set,
with the protocol’s explicit exceptions, before dispatching the requested
operation. Follow-up request-signing and checksum regressions are documented in
the signed-header review.
Operators must update the Server to source containing the fix or a future release that explicitly includes it. Restrict write-signing credentials to the required objects and avoid exposing unnecessary read grants or anonymous readable upload destinations while planning that update. Updating a client or Console alone does not remove the Server defect.
Reported by Oren Yomtov. The canonical advisory ledger records SN-2026-011 and its source fix; a CVE was requested. Do not substitute a dependency scan’s clean reachability result for this application-level status. See the component matrix for released versus main source and the Server changelog for the remaining release contents.