<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:59:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15463</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15463</link>
      <description>bdu:2026-15463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15463</guid>
    </item>
    <item>
      <title>BIT-minio-2026-39414 — MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing</title>
      <link>https://cve.radiocsirt.org/vuln/bit-minio-2026-39414</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader&amp;#39;s nextSplit() function calls bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;) with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: minio&lt;/p&gt;
&lt;p&gt;MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader&amp;#39;s nextSplit() function calls bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;) with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-minio-2026-39414</guid>
    </item>
    <item>
      <title>EUVD-2026-290269</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290269</link>
      <description>EUVD-2026-290269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290269</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39414</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39414</link>
      <description>&lt;p&gt;MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader&amp;#39;s nextSplit() function calls bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;) with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader&amp;#39;s nextSplit() function calls bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;) with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39414</guid>
    </item>
    <item>
      <title>GHSA-h749-fxx7-pwpg — MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h749-fxx7-pwpg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/minio/minio&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV 
files containing lines longer than available memory. The CSV reader&amp;#39;s `nextSplit()` 
function calls `bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;)` with no size limit, buffering the entire 
input in memory until a newline is found. A CSV file with no newline characters 
causes the entire contents to be read into a single allocation, leading to an OOM
crash of the MinIO server process.&lt;/p&gt;
&lt;p&gt;This is exploitable by any authenticated user with `s3:PutObject` and `s3:GetObject` 
permissions. The attack is especially practical when combined with compression: 
a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without 
newlines, allowing a small upload to cause large memory consumption on 
the server. However, compression is not required — a sufficiently large uncompressed 
CSV with no newlines triggers the same issue.&lt;/p&gt;
&lt;p&gt;**Affected component:** `internal/s3select/csv/reader.go`, function
`nextSplit()`.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-770 (Allocation of Resources Without Limits or Throttling)&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;All MinIO releases are through the final release of the minio/minio open-source project.&lt;/p&gt;
&lt;p&gt;The vulnerability was introduced in commit https://github.com/minio/minio/commit/7c14cdb60e53dbfdad2be644dfb180cab19fffa7, which added S3 Select support for CSV. 
The CSV reader has used unbounded line reads since this commit (originally via 
Go&amp;#39;s stdlib `encoding…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/minio/minio&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;MinIO&amp;#39;s S3 Select feature is vulnerable to memory exhaustion when processing CSV 
files containing lines longer than available memory. The CSV reader&amp;#39;s `nextSplit()` 
function calls `bufio.Reader.ReadBytes(&amp;#39;\n&amp;#39;)` with no size limit, buffering the entire 
input in memory until a newline is found. A CSV file with no newline characters 
causes the entire contents to be read into a single allocation, leading to an OOM
crash of the MinIO server process.&lt;/p&gt;
&lt;p&gt;This is exploitable by any authenticated user with `s3:PutObject` and `s3:GetObject` 
permissions. The attack is especially practical when combined with compression: 
a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without 
newlines, allowing a small upload to cause large memory consumption on 
the server. However, compression is not required — a sufficiently large uncompressed 
CSV with no newlines triggers the same issue.&lt;/p&gt;
&lt;p&gt;**Affected component:** `internal/s3select/csv/reader.go`, function
`nextSplit()`.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-770 (Allocation of Resources Without Limits or Throttling)&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;All MinIO releases are through the final release of the minio/minio open-source project.&lt;/p&gt;
&lt;p&gt;The vulnerability was introduced in commit https://github.com/minio/minio/commit/7c14cdb60e53dbfdad2be644dfb180cab19fffa7, which added S3 Select support for CSV. 
The CSV reader has used unbounded line reads since this commit (originally via 
Go&amp;#39;s stdlib `encoding…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h749-fxx7-pwpg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1016 — MinIO: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1016</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in MinIO ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in MinIO ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1016</guid>
    </item>
  </channel>
</rss>
