<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Storage REST on SILO</title><link>https://silo.pgsty.com/tags/storage-rest/</link><description>Recent content in Storage REST on SILO</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 02 Aug 2026 15:22:46 +0800</lastBuildDate><atom:link href="https://silo.pgsty.com/tags/storage-rest/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-42600: ReadMultiple Storage-REST Path Traversal</title><link>https://silo.pgsty.com/blog/security/cve-2026-42600/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/security/cve-2026-42600/</guid><description>&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Released&lt;br&gt;
&lt;strong&gt;First containing release:&lt;/strong&gt; &lt;a href="https://github.com/pgsty/minio/releases/tag/RELEASE.2026-06-18T00-00-00Z"&gt;RELEASE.2026-06-18T00-00-00Z&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;GitHub advisory:&lt;/strong&gt; &lt;a href="https://github.com/advisories/GHSA-xh8f-g2qw-gcm7"&gt;GHSA-xh8f-g2qw-gcm7&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Affected scope:&lt;/strong&gt; Distributed erasure only; cluster-root / internode JWT required&lt;/p&gt;
&lt;p&gt;The msgpack body of &lt;code&gt;/rmpl&lt;/code&gt; carried &lt;code&gt;Bucket&lt;/code&gt;, &lt;code&gt;Prefix&lt;/code&gt;, and &lt;code&gt;Files&lt;/code&gt;. The old code joined those values into filesystem paths without a containment check. The initial fix implemented full preflight validation. Continued call-chain review then found that this API had had no production caller since 2024. The final solution changed from “retain and harden” to removing the route, handler, client, interface, and generated code.&lt;/p&gt;</description></item></channel></rss>