<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>BLOG on SILO</title><link>https://silo.pgsty.com/module/blog/</link><description>Recent content in BLOG on SILO</description><generator>Hugo</generator><language>en</language><atom:link href="https://silo.pgsty.com/module/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Posts</title><link>https://silo.pgsty.com/blog/post/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/post/</guid><description>&lt;p&gt;Essays and analysis about MinIO, S3-compatible object storage, and the SILO community fork.&lt;/p&gt;</description></item><item><title>Release Notes</title><link>https://silo.pgsty.com/blog/release/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/release/</guid><description>&lt;p&gt;Each published SILO version has its own page with the release date, major changes, security fixes, dependency updates, and related commits.&lt;/p&gt;</description></item><item><title>SILO Security Chronicle</title><link>https://silo.pgsty.com/blog/security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/security/</guid><description>&lt;p&gt;This is the security chronicle of the SILO community fork. It follows the incidents in the order they were investigated and fixed. Each CVE has its own article: the original threat model, the turns taken during review, the rejected alternatives, the final invariant, the evidence, and the compatibility cost all stay with that incident.&lt;/p&gt;
&lt;h2 id="chronicle"&gt;Chronicle&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th style="text-align: left"&gt;Date&lt;/th&gt;
 &lt;th style="text-align: left"&gt;CVE&lt;/th&gt;
 &lt;th style="text-align: left"&gt;Incident&lt;/th&gt;
 &lt;th style="text-align: left"&gt;First containing release&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-15&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-32285&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-32285/"&gt;The &lt;code&gt;jsonparser&lt;/code&gt; advisory that required no patch&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;Already fixed in the dependency graph&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-15&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-33322&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-33322/"&gt;OIDC JWT algorithm confusion&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-15&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-33419&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-33419/"&gt;LDAP STS enumeration and throttling&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17; completed in 2026-06-18&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-15&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-34204&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-34204/"&gt;Replication metadata injection&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-15&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-39414&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-39414/"&gt;Oversized records in S3 Select&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17; completed in 2026-06-18&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-16&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-40344&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-40344/"&gt;Snowball auto-extract authentication bypass&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-04-16&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-41145&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-41145/"&gt;Unsigned-trailer query authentication bypass&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-04-17&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;2026-06-12&lt;/td&gt;
 &lt;td style="text-align: left"&gt;CVE-2026-42600&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-42600/"&gt;&lt;code&gt;ReadMultiple&lt;/code&gt; storage-REST path traversal&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: left"&gt;SILO 2026-06-18&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The articles below are ordered chronologically; incidents investigated on the same day are ordered by CVE number. Dependency-only CVEs remain in the relevant &lt;a href="https://silo.pgsty.com/blog/release/"&gt;release notes&lt;/a&gt; instead of being inflated into application-level incident stories.&lt;/p&gt;</description></item></channel></rss>