SCA: security update for github.com/minio/minio (GHSA-hv4r-mvr4-25vw)

high Tenable Self-Hosted Container Security Plugin ID 446658

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to
RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-
PAYLOAD-TRAILER` code path allows any user who knows a valid access key to write arbitrary objects to any
bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment
is impacted. The attack requires only a valid access key (the well-known default `minioadmin`, or any key
with WRITE permission on a bucket) and a target bucket name. `PutObjectHandler` and `PutObjectPartHandler`
call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the
`Authorization` header. Meanwhile, `isPutActionAllowed` extracts credentials from either the
`Authorization` header or the `X-Amz-Credential` query parameter, and trusts whichever it finds. An
attacker omits the `Authorization` header and supplies credentials exclusively via the query string. The
signature gate evaluates to `false`, `doesSignatureMatch` is never called, and the request proceeds with
the permissions of the impersonated access key. This affects `PutObjectHandler` (standard and
tables/warehouse bucket paths) and `PutObjectPartHandler` (multipart uploads). Users of the open-source
`minio/minio` project should upgrade to MinIO AIStor `RELEASE.2026-04-11T03-20-12Z` or later. If upgrading
is not immediately possible, block unsigned-trailer requests at the load balancer. Reject any request
containing `X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER` at the reverse proxy or WAF layer.
Clients can use `STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER` (the signed variant) instead. Alternatively,
restrict WRITE permissions. Limit `s3:PutObject` grants to trusted principals. While this reduces the
attack surface, it does not eliminate the vulnerability since any user with WRITE permission can exploit
it with only their access key. (CVE-2026-41145)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-hv4r-mvr4-25vw

Plugin Details

Severity: High

ID: 446658

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 52.01

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:P

CVSS Score Source: CVE-2026-41145

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.8

Threat Score: 6.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/14/2026

Vulnerability Publication Date: 4/14/2026

Reference Information

CVE: CVE-2026-41145

cwe: CWE-287