CVE-2026-34204

MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*

History

07 Apr 2026, 16:06

Type Values Removed Values Added
References () https://github.com/minio/minio/security/advisories/GHSA-3rh2-v3gr-35p9 - () https://github.com/minio/minio/security/advisories/GHSA-3rh2-v3gr-35p9 - Vendor Advisory
CPE cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
First Time Minio
Minio minio

31 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 20:16

Updated : 2026-06-17 10:38


NVD link : CVE-2026-34204

Mitre link : CVE-2026-34204

CVE.ORG link : CVE-2026-34204


JSON object : View

Products Affected

minio

  • minio
CWE
CWE-287

Improper Authentication