Skip to content

Tags: Security

  • September Security Repairs: Payload Integrity, IAM Revocation and Console Sharing

    In Security

    SecuritySigV4IAMConsole

    September Security Repairs: Payload Integrity, IAM Revocation and Console Sharing

    This record covers three repairs and their delivery boundaries as of September 16. The identifiers are SILO-local advisory numbers, not CVEs or assigned CVSS scores. The security ledger is the maintained index. Finding Fixed source Published delivery …

    This record covers three repairs and their delivery boundaries as of September 16. The identifiers are SILO-local advisory numbers, not CVEs or assigned CVSS scores. The security ledger is the maintained index. Finding Fixed source Published delivery …

  • SN-2026-011: Fix and Release Status

    In Security

    Securitysilo

    SN-2026-011: Fix and Release Status

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

  • An Unsigned Header Is Not Part of the Request

    In Design

    DesignSecuritySigV4CopyObjectPresignedCompatibility

    An Unsigned Header Is Not Part of the Request

    This record describes the unsigned-header coverage repair committed to SILO as 123325430 and merged through PR #173, tracked as SN-2026-011. It was reported by Oren Yomtov against a released build and reproduced locally on both signature paths. …

    This record describes the unsigned-header coverage repair committed to SILO as 123325430 and merged through PR #173, tracked as SN-2026-011. It was reported by Oren Yomtov against a released build and reproduced locally on both signature paths. …

  • SILO Server 20260903 Pre-release Review

    In Design

    DesignReviewSecurityCompatibilityRelease

    SILO Server 20260903 Pre-release Review

    This is the durable pre-release engineering record behind SILO 20260903. It explains why an earlier “all issues are solved” assessment was not accepted at face value, what the independent review found, how the fixes were narrowed, and which gates …

    This is the durable pre-release engineering record behind SILO 20260903. It explains why an earlier “all issues are solved” assessment was not accepted at face value, what the independent review found, how the fixes were narrowed, and which gates …

  • SILO 20260903 Security Notes: SN-2026-006 through 010

    In Security

    SecurityS3SSE-CReplicationIAM

    SILO 20260903 Security Notes: SN-2026-006 through 010

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

  • Explicit Version Deletes Now Require DeleteObjectVersion

    In Release

    ReleaseSecurityIAMS3Compatibility

    Explicit Version Deletes Now Require DeleteObjectVersion

    Release status: this change is implemented in pgsty/silo#104, tracking issue #58. Publishing this note does not by itself mean that a server release, package, image, or deployment contains the change. SILO now maps object-delete authorization to the …

    Release status: this change is implemented in pgsty/silo#104, tracking issue #58. Publishing this note does not by itself mean that a server release, package, image, or deployment contains the change. SILO now maps object-delete authorization to the …

  • No I/O Before Auth, No Privilege From Headers

    In Design

    DesignSecurityCORSReplicationSSE-CCompatibility

    No I/O Before Auth, No Privilege From Headers

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

  • One Endpoint, Two Privileges: Separating User and Group Status

    In Design

    DesignIAMSecurityCompatibility

    One Endpoint, Two Privileges: Separating User and Group Status

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

    Release check (2026-09-16): the original repair described here is included in Server 20260903. Dated review and test accounts below record their original evidence, not a still-pending release or acceptance of a particular production installation. …

  • silo-pkg 3.12.0 Released

    In Release

    ReleasepkgSecurity

    silo-pkg 3.12.0 Released

    Release date: 2026-08-24 · Version: v3.12.0 · Commit: 2b087a1 · Repository: pgsty/silo-pkg Version 3.12.0 is a main-line minor release with two themes: a policy-write guard for ARN prefixes that name no resource, and the maintained Go 1.27 / etcd 3.7 …

    Release date: 2026-08-24 · Version: v3.12.0 · Commit: 2b087a1 · Repository: pgsty/silo-pkg Version 3.12.0 is a main-line minor release with two themes: a policy-write guard for ARN prefixes that name no resource, and the maintained Go 1.27 / etcd 3.7 …

  • Preview Text, Never Execute It: SILO Console Text Preview PRD

    In Design

    DesignConsolepreviewSecurity

    Preview Text, Never Execute It: SILO Console Text Preview PRD

    Status: shipped in SILO Console 2.2.0 · Owner: pgsty/silo-console · Tracking: pgsty/silo#17 · Review: consensus of product, security, and frontend architecture reviews SILO Console can preview images, PDFs, audio, and video, but not the small logs, …

    Status: shipped in SILO Console 2.2.0 · Owner: pgsty/silo-console · Tracking: pgsty/silo#17 · Review: consensus of product, security, and frontend architecture reviews SILO Console can preview images, PDFs, audio, and video, but not the small logs, …

  • Three Headers, One Lie: Making the Client Source Address Mean Something

    In Security

    SecuritySource Address

    Three Headers, One Lie: Making the Client Source Address Mean Something

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    In Security

    SecurityVersion ID

    Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    In Security

    SecurityObject Grant

    Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

  • The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    In Security

    SecurityBucket Notifications

    The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    In Security

    SecurityMultipart Upload

    Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

  • Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    In Security

    SecurityPath Containment

    Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    In Security

    SecurityReadMultiple

    CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    In Security

    SecurityUnsigned Trailer

    CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    In Security

    SecuritySnowball

    CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    In Security

    SecurityS3 Select

    CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    SecurityReplication

    CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    In Security

    SecurityLDAP STS

    CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    In Security

    SecurityOIDC

    CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

  • CVE-2026-32285: The jsonparser Advisory That Required No Patch

    In Security

    Securityjsonparser

    CVE-2026-32285: The jsonparser Advisory That Required No Patch

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

  • CVE-2025-62506: Session-Policy Privilege Escalation

    In Security

    SecurityIAM

    CVE-2025-62506: Session-Policy Privilege Escalation

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …