{"id":"CVE-2026-97731","published":"2026-09-25T03:16:59.697","lastModified":"2026-09-25T16:17:31.127","description":"MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected.","cvssScore":7.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwes":["CWE-347"],"vendors":[],"products":[],"references":[{"url":"https://github.com/pgsty/silo/commit/1233254309b15571f101b2b26d531951ceaeef1e","tags":[]},{"url":"https://silo.pgsty.com/about/security-advisories/#sn-2026-011","tags":[]}],"exploitRefs":[{"url":"https://github.com/pgsty/silo/commit/1233254309b15571f101b2b26d531951ceaeef1e","tags":[]}],"hasPoc":true,"ai":null}