CVE-2025-31489: MinIO performs incomplete signature validation for unsigned-trailer uploads

Published Apr 3, 2025
·
Updated

Impact This is a high priority vulnerability and users must upgrade ASAP.

The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on the bucket,

Prior knowledge of access-key, and bucket name this user might have access to - and an access-key with a WRITE permissions is necessary.

However with relevant information in place, uploading random objects to buckets is trivial and easy via curl

Patches Yes https://github.com/minio/minio/pull/21103

Workarounds Reject requests with x-amz-content-sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER for now at LB layer, ask application users to use STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER

Other sources

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on the bucket. Prior knowledge of access-key, and bucket name this user might have access to - and an access-key with a WRITE permissions is necessary. However with relevant information in place, uploading random objects to buckets is trivial and easy via curl. This issue is fixed in RELEASE.2025-04-03T14-56-28Z.

MITRE

Affected Software

2 affected componentsFixes available
MinIO<RELEASE.2025-04-03T14-56-28Z
go/github.com/minio/minio<0.0.0-20250403145552-8c70975283f9
0.0.0-20250403145552-8c70975283f9

Event History

Apr 3, 2025
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Apr 4, 2025
Advisory Published
via GitHub·02:28 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-31489?

CVE-2025-31489 has a high severity rating due to the risk of unauthorized object uploads.

2

How do I fix CVE-2025-31489?

To fix CVE-2025-31489, upgrade to a version of MinIO released after April 3, 2025.

3

What components of MinIO are impacted by CVE-2025-31489?

CVE-2025-31489 affects the signature component of MinIO's authorization process.

4

Can CVE-2025-31489 be exploited without authentication?

Yes, if a user has write permissions, CVE-2025-31489 can be exploited using arbitrary secrets.

5

Is there a workaround for CVE-2025-31489 before upgrading?

There are no documented workarounds; upgrading to a secure version is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203