---
id: CVE-2025-59952
title: >-
  MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket
  and object operations to any Amazon S3 compatible object storage service
summary: >-
  MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket
  and object operations to any Amazon S3 compatible object storage service. In
  minio-java versions prior to 8.6.0, XML tag values containing references to
  system …
severity: none
cwe:
  - CWE-20
  - CWE-94
published: '2025-09-30'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59952'
references:
  - url: >-
      https://github.com/minio/minio-java/commit/f7a98d06b25e5464bdd4811b044e25ff9101d37f
    label: security-advisories@github.com
  - url: 'https://github.com/minio/minio-java/releases/tag/8.6.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/minio/minio-java/security/advisories/GHSA-h7rh-xfpj-hpcm
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00491
epssPercentile: 0.40264
ingestedAt: '2026-10-09T09:31:00.994Z'
---

## Overview

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
