GPU VulnDB

Database/Control plane, storage & DevOps

MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is not

CVE-2026-41145Control plane, storage & DevOpscurated

Impact

The signature on a query-string-credential unsigned-trailer upload is not properly verified, so an attacker with no valid secret key writes objects into buckets they have no rights to. Anyone who can reach the endpoint can overwrite a checkpoint, a dataset shard, or a model artifact belonging to another tenant.

Who can reach it

Any client that can reach the MinIO S3 endpoint over the network. No valid credential is needed.

What to do

Upgrade MinIO to the release named in GHSA-hv4r-mvr4-25vw and restart every node in the erasure set (rolling restart is supported). Afterwards audit object versions and modification times on buckets that were internet- or tenant-reachable, and turn on versioning plus object lock for artifacts you cannot afford to have silently rewritten.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.