7.5
CWE
400
Advisory Published
Updated

CVE-2022-31028: Possible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO

First published: Fri Jun 03 2022(Updated: )

MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing the connections. Public-facing MinIO deployments are most affected. Users should upgrade to RELEASE.2022-06-02T02-11-04Z to receive a patch. One possible workaround is to use a reverse proxy to limit the number of connections being attempted in front of MinIO, and actively rejecting connections from such malicious clients.

Credit: security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
MinIO MinIO>=2019-09-25t18-25-51z<2022-06-02t02-11-04z

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-31028?

    CVE-2022-31028 is classified as a medium severity vulnerability.

  • How do I fix CVE-2022-31028?

    To fix CVE-2022-31028, it is recommended to upgrade MinIO to version RELEASE.2022-06-03T01-40-53Z or later.

  • What type of vulnerability is CVE-2022-31028?

    CVE-2022-31028 involves an unending go-routine buildup due to HTTP clients not closing connections properly.

  • What versions of MinIO are affected by CVE-2022-31028?

    CVE-2022-31028 affects MinIO versions from RELEASE.2019-09-25T18-25-51Z to RELEASE.2022-06-02T02-11-04Z.

  • What impact does CVE-2022-31028 have on MinIO?

    The impact of CVE-2022-31028 can lead to resource exhaustion and degraded performance due to the accumulation of go-routines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203