Skip to content

SILO Security Chronicle

This is the security chronicle of the SILO community fork, listed from newest to oldest. Each CVE has its own article: the original threat model, the turns taken during review, the rejected alternatives, the final invariant, the evidence, and the compatibility cost all stay with that incident.

  • SN-2026-011: Fix and Release Status

    In Security

    Securitysilo

    Featured Image for SN-2026-011: Fix and Release Status

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

    Status on 2026-09-13: SN-2026-011 is fixed on Server main, starting with 123325430. The latest published Server, RELEASE.2026-09-03T13-18-01Z, and earlier public Server releases are affected. No new fixed Server release is established by the pkg …

  • SILO 20260903 Security Notes: SN-2026-006 through 010

    In Security

    SecurityS3SSE-CReplicationIAM

    Featured Image for SILO 20260903 Security Notes: SN-2026-006 through 010

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

    Released in SILO 20260903. These fixes are part of RELEASE.2026-09-03T13-18-01Z. See the complete release notes for the 20260806-to-20260903 upgrade boundary, components, verification evidence, and known deferrals. This bulletin collects five …

  • Three Headers, One Lie: Making the Client Source Address Mean Something

    In Security

    SecuritySource Address

    Featured Image for Three Headers, One Lie: Making the Client Source Address Mean Something

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    In Security

    SecurityVersion ID

    Featured Image for Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    In Security

    SecurityObject Grant

    Featured Image for Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

  • The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    In Security

    SecurityBucket Notifications

    Featured Image for The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: …

  • Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    In Security

    SecurityMultipart Upload

    Featured Image for Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Classification: Data …

  • Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    In Security

    SecurityPath Containment

    Featured Image for Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

    Release status (verified 2026-09-13): the primary fix in this article is included in 20260804 and later releases. The investigation below retains its original test boundaries; see the component matrix for current unreleased work. Affected scope: …

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    In Security

    SecurityReadMultiple

    Featured Image for CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    In Security

    SecurityUnsigned Trailer

    Featured Image for CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    In Security

    SecuritySnowball

    Featured Image for CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    In Security

    SecurityS3 Select

    Featured Image for CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    SecurityReplication

    Featured Image for CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    In Security

    SecurityLDAP STS

    Featured Image for CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    In Security

    SecurityOIDC

    Featured Image for CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

  • CVE-2026-32285: The jsonparser Advisory That Required No Patch

    In Security

    Securityjsonparser

    Featured Image for CVE-2026-32285: The jsonparser Advisory That Required No Patch

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

  • CVE-2025-62506: Session-Policy Privilege Escalation

    In Security

    SecurityIAM

    Featured Image for CVE-2025-62506: Session-Policy Privilege Escalation

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …

    Status: Inherited and released First Silo community release: RELEASE.2025-12-03T12-00-00Z Upstream fixed release: RELEASE.2025-10-15T17-29-55Z GitHub advisory: GHSA-jjjj-jwhf-8rgr Upstream fix: minio/minio#21642 A service account or STS account with …