MinIO has 6 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.1 (high), with 1 rated critical. 17% have been exploited in the wild — well above the 1% corpus average, so MinIO flaws are worth patching on sight. Most affected products: github.com/minio/minio (5), MinIO (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 17% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —(1)
- Last 90 days
- 1 prev 1
Weakness classes
Products
- github.com/minio/minio 5
- MinIO 1
Worst active — by depth score
CVE-2023-28434High· 8.8Privilege Escalation on Linux/MacOS75CVE-2025-31489HighMinIO performs incomplete signature validation for unsigned-trailer uploads54CVE-2026-33322CriticalMinIO has JWT Algorithm Confusion in OIDC Authentication52CVE-2026-39414HighMinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing41CVE-2026-97731High· 7.1MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list39
MinIO vulnerabilities
CVEs affecting MinIO, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-97731High· 7.1MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and nev…
CVE-2026-39414HighMinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVE-2026-34204High· 7.1MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
CVE-2026-33322CriticalMinIO has JWT Algorithm Confusion in OIDC Authentication
MinIO has JWT Algorithm Confusion in OIDC Authentication
CVE-2025-31489HighPoCMinIO performs incomplete signature validation for unsigned-trailer uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS