SILO Security Chronicle
This is the security chronicle of the SILO community fork, listed from newest to oldest. Each CVE has its own article: the original threat model, the turns taken during review, the rejected alternatives, the final invariant, the evidence, and the compatibility cost all stay with that incident.
-
SN-2026-011: Fix and Release Status
Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …
Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …
-
SILO 20260903 Security Notes: SN-2026-006 through 010
Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …
Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …
-
Three Headers, One Lie: Making the Client Source Address Mean Something
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
-
Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
-
Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself
Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …
Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …
-
The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …
-
Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …
-
Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …
Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …
-
CVE-2026-42600: ReadMultiple Storage-REST Path Traversal
Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …
Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …
-
CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …
-
CVE-2026-40344: Snowball Auto-Extract Authentication Bypass
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …
-
CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass
Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …
Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …
-
CVE-2026-34204: Replication Metadata Injection
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …
-
CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain
Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …
Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …
-
CVE-2026-33322: OIDC JWT Algorithm Confusion
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …
Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …
-
CVE-2026-32285: The jsonparser Advisory That Required No Patch
Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …
Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …
-
CVE-2025-62506: Session-Policy Privilege Escalation
Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …
Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …