GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (S3 API, Snowball auto-extract): MULTI-TENANT ISOLATION: the Snowball auto-extract path skips signature

CVE-2026-40344Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: the Snowball auto-extract path skips signature verification entirely, so an unauthenticated caller uploads a TAR that MinIO unpacks into arbitrary object keys. That is unauthenticated write into any bucket - dataset poisoning and checkpoint tampering across tenant boundaries.

Who can reach it

Any client with network reach to the MinIO S3 endpoint. Pre-authentication.

What to do

Upgrade MinIO to the fixed release from GHSA-9c4q-hq6p-c237 and roll a restart across the cluster. If you do not use Snowball ingestion, block the x-minio-extract / snowball request path at the proxy as an interim control, and review object write history on shared buckets.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.