MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsigned X‑Amz‑Headers Enable Server‑Side Copy via Presigned PUT URLs in MinIO |
Fri, 25 Sep 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected. | |
| First Time appeared |
Minio
Minio minio |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Minio
Minio minio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T03:07:30.661Z
Reserved: 2026-09-25T03:07:29.873Z
Link: CVE-2026-97731
No data.
Status : Received
Published: 2026-09-25T03:16:59.697
Modified: 2026-09-25T03:16:59.697
Link: CVE-2026-97731
No data.
OpenCVE Enrichment
Updated: 2026-09-25T09:30:07Z
Weaknesses