CVE-2026-39414: MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

Published Apr 8, 2026
·
Updated

Impact

What kind of vulnerability is it? Who is impacted?

MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader's nextSplit() function calls bufio.Reader.ReadBytes('\n') with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process.

This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.

Affected component: internal/s3select/csv/reader.go, function nextSplit().

CWE: CWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Versions

All MinIO releases are through the final release of the minio/minio open-source project.

The vulnerability was introduced in commit https://github.com/minio/minio/commit/7c14cdb60e53dbfdad2be644dfb180cab19fffa7, which added S3 Select support for CSV. The CSV reader has used unbounded line reads since this commit (originally via Go's stdlib encoding/csv.Reader, later via bufio.Reader.ReadBytes after a refactor in PR #8200.

The first affected release is RELEASE.2018-08-18T03-49-57Z.

Patches

Fixed in: MinIO AIStor RELEASE.2025-12-20T04-58-37Z

The fix replaces the unbounded bufio.Reader.ReadBytes('\n') call with a byte-at-a-time loop that caps line scanning at 128 KB (csvSplitSize). If no newline is found within this limit, the reader returns an error instead of continuing to buffer.

Binary Downloads

| Platform | Architecture | Download | | -------- | ------------ | --------------------------------------------------------------------------- | | Linux | amd64 | minio | | Linux | arm64 | minio | | macOS | arm64 | minio | | macOS | amd64 | minio | | Windows | amd64 | minio.exe |

FIPS Binaries

| Platform | Architecture | Download | | -------- | ------------ | --------------------------------------------------------------------------- | | Linux | amd64 | minio.fips | | Linux | arm64 | minio.fips |

Package Downloads

| Format | Architecture | Download | | ------ | ------------ | ----------------------------------------------------------------------------------------------------------------------------------- | | DEB | amd64 | minio20251220045837.0.0amd64.deb | | DEB | arm64 | minio20251220045837.0.0arm64.deb | | RPM | amd64 | minio-20251220045837.0.0-1.x8664.rpm | | RPM | arm64 | minio-20251220045837.0.0-1.aarch64.rpm |

Container Images

bash Standard docker pull quay.io/minio/aistor/minio:RELEASE.2025-12-20T04-58-37Z podman pull quay.io/minio/aistor/minio:RELEASE.2025-12-20T04-58-37Z

FIPS docker pull quay.io/minio/aistor/minio:RELEASE.2025-12-20T04-58-37Z.fips podman pull quay.io/minio/aistor/minio:RELEASE.2025-12-20T04-58-37Z.fips

Homebrew (macOS)

bash brew install minio/aistor/minio

Workarounds

- Users of the open-source minio/minio project should upgrade to MinIO AIStor RELEASE.2025-12-20T04-58-37Z or later.

If upgrading is not immediately possible:

- Disable S3 Select access via IAM policy. Deny the s3:GetObject action with a condition restricting s3:prefix on sensitive buckets, or more specifically, deny SelectObjectContent requests at a reverse proxy by blocking POST requests with ?select&select-type=2 query parameters.

- Restrict PutObject permissions. Limit s3:PutObject grants to trusted principals to reduce the attack surface. Note: this reduces risk but does not eliminate the vulnerability since any authorized user can exploit it.

References

- Introducing commit: 7c14cdb60 (PR #6127) - MinIO AIStor

Other sources

MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader's nextSplit() function calls bufio.Reader.ReadBytes('\n') with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.

MITRE

Affected Software

2 affected components
go/github.com/minio/minio>=0.0.0-20180815103019-7c14cdb60e53<=0.0.0-20251203081239-27742d469462
MinIO MinIO>=2018-08-18t03-49-57z<=2025-10-15t17-29-55z

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade minio/aistor to a version that resolves this vulnerability.

    Fixed in RELEASE.2025-12-20T04-58-37ZPatch 7c14cdb60
  2. Configuration

    Disable S3 Select access by denying the `s3:GetObject` action (e.g., via an IAM policy conditionally applied to S3 Select usage).

    S3 IAM policy for S3 Select Deny s3:GetObject = s3:GetObject
  3. Configuration

    Reduce attack surface by limiting `s3:PutObject` permissions to trusted principals/users only.

    S3 IAM policy for S3 PutObject Restrict s3:PutObject grants = Limit `s3:PutObject` grants to trusted principals
  4. Compensating control

    If upgrading is not immediately possible, reduce exposure by denying `SelectObjectContent` requests at a reverse proxy (as a mitigation to S3 Select abuse).

  5. Compensating control

    Further restrict access by using an IAM condition restricting `s3:prefix` on sensitive buckets (to limit where S3 Select can be invoked).

Event History

Apr 8, 2026
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
RemedyAffected Software
Apr 9, 2026
Advisory Published
via GitHub·05:32 PM
Data Sourced
via GitHub·05:32 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-39414?

CVE-2026-39414 is classified as a denial-of-service vulnerability due to unbounded memory allocation.

2

Who is affected by CVE-2026-39414?

Users of MinIO's S3 Select feature who process CSV files with excessively long lines are affected by CVE-2026-39414.

3

How do I fix CVE-2026-39414?

To mitigate CVE-2026-39414, update MinIO to the latest version that addresses the memory exhaustion issue.

4

What type of attack does CVE-2026-39414 enable?

CVE-2026-39414 enables denial-of-service attacks through memory exhaustion when handling large CSV files.

5

Can CVE-2026-39414 be exploited remotely?

Yes, CVE-2026-39414 can be exploited remotely by sending specially crafted CSV files to the vulnerable MinIO server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203