-Infinity
0

Vendor Risk Score

See how minio compares to other vendors in security performance

View Risk Score →

go/github.com/minio/minioMinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

Risk 36
Severity
6.9
First published (updated )

MinIO MinIOMinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads

Risk 57
Severity
8.8
First published (updated )

MinIO MinIOMinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads

Risk 57
Severity
8.8
First published (updated )

go/github.com/minio/minioMinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

Risk 40
Severity
7.1
First published (updated )

go/github.com/minio/minioMinIO is Vulnerable to SSE Metadata Injection via Replication Headers

Risk 49
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/minio/minioMinIO: LDAP login brute-force via user enumeration and missing rate limit

Risk 45
Severity
9.1
EPSS
0.05%
First published (updated )

go/github.com/minio/minioMinIO: JWT Algorithm Confusion in OIDC Authentication

Risk 61
Severity
9.2
EPSS
0.02%
First published (updated )

MinIO MinIOMinIO vulnerable to privilege escalation via session policy bypass in service accounts and STS

Risk 60
Severity
8.1
First published (updated )

MinIO Java SDKMinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations t…

Risk 33
Severity
7
First published (updated )

MinIO minio-javaminio-java Client XML Tag is Vulnerable to Value Substitution

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MinIOMinIO performs incomplete signature validation for unsigned-trailer uploads

Risk 34
Severity
8.7
EPSS
1.05%
First published (updated )

MinIOMinIO SFTP authentication bypass due to improperly trusted SSH key

Risk 23
Severity
4.6
EPSS
0.20%
First published (updated )

go/github.com/minio/minioMinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation

Risk 73
Severity
8.8
EPSS
0.06%
First published (updated )

go/github.com/minio/consoleMinio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited

Risk 27
Severity
5.3
First published (updated )

MinIOMinIO Security Feature Bypass Vulnerability

Risk 95
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/minio/minioMinio Privilege Escalation on Windows via Path separator manipulation

Risk 80
Severity
8.8
First published (updated )

MinIOMinIO Information Disclosure Vulnerability

Risk 65
Severity
7.5
First published (updated )

MinIOMinio vulnerable to denial of access by an admin privileged user for root credential

Risk 49
Severity
6.5
First published (updated )

MinIOAllowed DELETE on resources on object locked buckets under Governance mode in Minio

Risk 79
Severity
8.8
First published (updated )

MinIOAuthenticated requests for server update admin API allows path traversal in minio

Risk 65
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MinIOPossible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIO

Risk 43
Severity
7.5
First published (updated )

MinIOImproper Privilege Management in MinIO

Risk 78
Severity
9
First published (updated )

redhat/RELEASE.2021-12-27T07-23User privilege escalation in MinIO

Risk 82
Severity
8.8
First published (updated )

MinIOBypassing policy restrictions on regular users

Risk 79
Severity
8.8
First published (updated )

MinIOMITM modification of request bodies in MinIO

Risk 37
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MinIOBypassing readOnly policy by creating a temporary 'mc share upload' URL

Risk 44
Severity
7.7
First published (updated )

MinIOServer-Side Request Forgery in MinIO Browser API

Risk 44
Severity
7.7
First published (updated )

MinIOAuthentication bypass MinIO Admin API

Risk 61
Severity
9.3
First published (updated )

MinIOMinio Inc. Minio S3 server version prior to RELEASE.2018-05-16T23-35-33Z contains a Allocation of Me…

Risk 43
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203