<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:24:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11031</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11031</link>
      <description>bdu:2026-11031</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11031</guid>
    </item>
    <item>
      <title>BIT-minio-2026-34204 — MinIO is Vulnerable to SSE Metadata Injection via Replication Headers</title>
      <link>https://cve.radiocsirt.org/vuln/bit-minio-2026-34204</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a high-performance object storage system. Prior to version 2026.03.26, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version 2026.03.26.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a high-performance object storage system. Prior to version 2026.03.26, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version 2026.03.26.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-minio-2026-34204</guid>
    </item>
    <item>
      <title>EUVD-2026-278430</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278430</link>
      <description>EUVD-2026-278430</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278430</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34204</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34204</link>
      <description>&lt;p&gt;MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34204</guid>
    </item>
    <item>
      <title>GHSA-3rh2-v3gr-35p9 — MinIO is Vulnerable to SSE Metadata Injection via Replication Headers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3rh2-v3gr-35p9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/minio/minio&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A flaw in `extractMetadataFromMime()` allows any authenticated user with `s3:PutObject` permission to inject internal server-side encryption metadata into objects by sending crafted `X-Minio-Replication-*` headers on a normal PutObject request. The server unconditionally maps these headers to `X-Minio-Internal-*` encryption metadata without verifying that the request is a legitimate replication request. Objects written this way carry bogus encryption keys and become **permanently unreadable** through the S3 API.&lt;/p&gt;
&lt;p&gt;Any authenticated user or service with `s3:PutObject` permission on any bucket can make objects permanently unreadable by injecting fake SSE encryption metadata. The attacker sends a standard PutObject request with `X-Minio-Replication-Server-Side-Encryption-*` headers but **without** the `X-Minio-Source-Replication-Request` header that marks legitimate replication traffic. The server maps these headers to internal encryption metadata (`X-Minio-Internal-Server-Side-Encryption-Sealed-Key`, etc.), causing all subsequent GetObject and HeadObject calls to treat the object as encrypted with keys that do not exist.&lt;/p&gt;
&lt;p&gt;This is a targeted denial-of-service vulnerability. An attacker can selectively corrupt individual objects or entire buckets. The `ReplicateObjectAction` IAM permission is never checked because the request is a normal PutObject, not a replication request.&lt;/p&gt;
&lt;p&gt;**Affected component:** `cmd/handler-uti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/minio/minio&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A flaw in `extractMetadataFromMime()` allows any authenticated user with `s3:PutObject` permission to inject internal server-side encryption metadata into objects by sending crafted `X-Minio-Replication-*` headers on a normal PutObject request. The server unconditionally maps these headers to `X-Minio-Internal-*` encryption metadata without verifying that the request is a legitimate replication request. Objects written this way carry bogus encryption keys and become **permanently unreadable** through the S3 API.&lt;/p&gt;
&lt;p&gt;Any authenticated user or service with `s3:PutObject` permission on any bucket can make objects permanently unreadable by injecting fake SSE encryption metadata. The attacker sends a standard PutObject request with `X-Minio-Replication-Server-Side-Encryption-*` headers but **without** the `X-Minio-Source-Replication-Request` header that marks legitimate replication traffic. The server maps these headers to internal encryption metadata (`X-Minio-Internal-Server-Side-Encryption-Sealed-Key`, etc.), causing all subsequent GetObject and HeadObject calls to treat the object as encrypted with keys that do not exist.&lt;/p&gt;
&lt;p&gt;This is a targeted denial-of-service vulnerability. An attacker can selectively corrupt individual objects or entire buckets. The `ReplicateObjectAction` IAM permission is never checked because the request is a normal PutObject, not a replication request.&lt;/p&gt;
&lt;p&gt;**Affected component:** `cmd/handler-uti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3rh2-v3gr-35p9</guid>
    </item>
  </channel>
</rss>
