Vulnerability Reportminio/minio:RELEASE.2025-09-07T16-13-09Z-cpuv1

minio/minio:RELEASE.2025-09-07T16-13-09Z-cpuv1
DIGESTsha256:13582eff79c6605a2d315bdd0e70164142ea7e98fc8411e9e10d089502a6d883

Executive Summary

Threat Score
50/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker with knowledge of a valid access key (including the default 'minioadmin') can exploit CVE-2026-40344 or CVE-2026-41145 to write arbitrary objects to any bucket without authentication. Additional issues like CVE-2025-68121 require specific TLS configuration mutations to be exploitable. Blocking unsigned-trailer requests at the load balancer fully mitigates the top two vulnerabilities. Note that CVE-2026-33322 (JWT algorithm confusion) only applies if OIDC authentication is enabled.

Vulnerabilities

Vulnerability Log

113 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-40344MEDIUM6.97
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-41145MEDIUM6.97
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2025-68121MEDIUM6.8
stdlib
v1.24.6
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33322MEDIUM6.66
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42151MEDIUM6.38
github.com/prometheus/prometheus
v0.303.0
fixed in 0.311.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42154MEDIUM6.38
github.com/prometheus/prometheus
v0.303.0
fixed in 0.311.3, 0.305.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61726MEDIUM6.38
stdlib
v1.24.6
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-25679MEDIUM6.38
stdlib
v1.24.6
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-32283MEDIUM6.38
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39820MEDIUM6.38
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-41602MEDIUM6.38
github.com/apache/thrift
v0.21.0
fixed in 0.23.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32285MEDIUM6.38
github.com/buger/jsonparser
v1.1.1
fixed in 1.1.2
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-34986MEDIUM6.38
github.com/go-jose/go-jose/v4
v4.1.0
fixed in 4.1.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33186MEDIUM6.18
google.golang.org/grpc
v1.71.0
fixed in 1.79.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33186MEDIUM6.18
google.golang.org/grpc
v1.72.0
fixed in 1.79.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34204MEDIUM6.03
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-6.el8_9
fixed in 2.48-6.el8_10.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.35.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.24.6
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39414MEDIUM5.52
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2019-14250MEDIUM5.5
libgcc
8.5.0-28.el8_10
No fix yet
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40179MEDIUM5.18
github.com/prometheus/prometheus
v0.303.0
fixed in 0.311.2-0.20260410083055-07c6232d159b
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-44903MEDIUM5.18
github.com/prometheus/prometheus
v0.303.0
fixed in 0.311.3
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM5.1
stdlib
v1.24.6
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281MEDIUM5.1
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33419MEDIUM5.1
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
glibc
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc-common
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc-minimal-langpack
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.3%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
8.5.0-28.el8_10
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.24.6
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.24.6
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.37
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc-common
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.37
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc-minimal-langpack
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.31
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.28-251.el8_10.25
fixed in 2.28-251.el8_10.37
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.40.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.40.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.24.6
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.24.6
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-10543MEDIUM4.5
github.com/eclipse/paho.mqtt.golang
v1.5.0
fixed in 1.5.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.37.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.37.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.28-251.el8_10.25
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.28-251.el8_10.25
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.28-251.el8_10.25
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-26958LOW3.15
filippo.io/edwards25519
v1.1.0
fixed in 1.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2018-20657LOW2.7
libgcc
8.5.0-28.el8_10
No fix yet
4.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.29
pcre2
10.32-3.el8_6
No fix yet
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-61728LOW2.29
stdlib
v1.24.6
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.30-15.el8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.24.6
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2021-39537NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
3.0%
Low-Moderate Risk
Not Applicable
CVE-2021-39537NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
3.0%
Low-Moderate Risk
Not Applicable
CVE-2020-19185NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-base
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
CVE-2018-19211NONE0
ncurses-libs
6.1-10.20180224.el8
No fix yet
0.9%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.24.6
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.24.6
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.24.6
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-62506NONE0
github.com/minio/minio
v0.0.0-20250907161309-07c3a429bfed+dirty
fixed in 0.0.0-20251015170045-c1a49490c78e
0.5%
Theoretical Threat
Not Applicable
CVE-2026-2303NONE0
go.mongodb.org/mongo-driver
v1.17.3
fixed in 1.17.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-24051NONE0
go.opentelemetry.io/otel/sdk
v1.35.0
fixed in 1.40.0
0.2%
Theoretical Threat
Not Applicable