Skip to content

PGSTY SILO Blog

  • Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    In Security

    securityVersion ID

    Featured Image for Absent Is Not Empty: A Blank versionid and the Fail-Open It Invites

    Status: Fixed on the local pgsty/minio branch as 744a9dcd7, unreleased Classification: Policy-enforcement correctness — a fail-closed report, a fail-open trap avoided, and one narrow trim bypass closed. Not a headline CVE — see How we classify this …

    Status: Fixed on the local pgsty/minio branch as 744a9dcd7, unreleased Classification: Policy-enforcement correctness — a fail-closed report, a fail-open trap avoided, and one narrow trim bypass closed. Not a headline CVE — see How we classify this …

  • Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    In Security

    securityObject Grant

    Featured Image for Object Grant, Bucket Reach: When 'bucket/*' Could Rewrite the Bucket Itself

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

    Status: Fixed on pgsty/silo-pkg main (3c24ad1, extended by 1f97549, scoped to its final twelve actions in d8b1fa7), released as silo-pkg v3.11.0; consumed by pgsty/minio Classification: Access-control hardening — a privilege boundary, narrowly …

  • The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    In Security

    securityBucket Notifications

    Featured Image for The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down

    Status: Fixed on the local pgsty/minio branch as 162ded343, unreleased Classification: Configuration-schema consistency and availability, not a vulnerability; includes one defensive hardening (credential values no longer echoed in validation errors) …

    Status: Fixed on the local pgsty/minio branch as 162ded343, unreleased Classification: Configuration-schema consistency and availability, not a vulnerability; includes one defensive hardening (credential values no longer echoed in validation errors) …

  • mcli 20260804 Released

    In Release

    Releasemcli

    Featured Image for mcli 20260804 Released

    Published: 2026-08-04 · Version: RELEASE.2026-08-04T00-00-00Z This is the first release of the pgsty/mc community fork since 20260417. It fixes a credential leak in debug logging, severs every remaining connection between the client and upstream …

    Published: 2026-08-04 · Version: RELEASE.2026-08-04T00-00-00Z This is the first release of the pgsty/mc community fork since 20260417. It fixes a credential leak in debug logging, severs every remaining connection between the client and upstream …

  • Silo Pkg 3.11.0 Released

    In Release

    Releasepkg

    Featured Image for Silo Pkg 3.11.0 Released

    Release date: 2026-08-04 · Version: v3.11.0 · Commit: d8b1fa7 · Repository: pgsty/silo-pkg This is the fork’s first pinned release. It restores the IAM bucket/object resource boundary reported as upstream minio/minio#20449: a policy condition-key …

    Release date: 2026-08-04 · Version: v3.11.0 · Commit: d8b1fa7 · Repository: pgsty/silo-pkg This is the fork’s first pinned release. It restores the IAM bucket/object resource boundary reported as upstream minio/minio#20449: a policy condition-key …

  • Silo Console 2.0.0 Released

    In Release

    ReleaseConsole

    Featured Image for Silo Console 2.0.0 Released

    Published: 2026-08-04 · Version: v2.0.0 · Repository: pgsty/silo-console SILO Console 2.0.0 is the first major release of this object-storage administration console as an independent project. Continuing from the georgmangold/console v1.9.1 …

    Published: 2026-08-04 · Version: v2.0.0 · Repository: pgsty/silo-console SILO Console 2.0.0 is the first major release of this object-storage administration console as an independent project. Continuing from the georgmangold/console v1.9.1 …

  • Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    In Security

    securityMultipart Upload

    Featured Image for Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    Status: Fixed on the local pgsty/minio branch as 22c1e41fd, unreleased Classification: Data correctness, not a vulnerability — see Why this is not a CVE Affected scope: All backends, any authenticated S3 client, on its own upload Tracking: …

    Status: Fixed on the local pgsty/minio branch as 22c1e41fd, unreleased Classification: Data correctness, not a vulnerability — see Why this is not a CVE Affected scope: All backends, any authenticated S3 client, on its own upload Tracking: …

  • Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    In Security

    securityPath Containment

    Featured Image for Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    Status: Fixed on the local pgsty/minio branch, unreleased and not disclosed (no CVE/GHSA requested; the upstream repository is archived) Affected scope: Distributed erasure only; cluster-root / internode JWT required Prerequisite reading: …

    Status: Fixed on the local pgsty/minio branch, unreleased and not disclosed (no CVE/GHSA requested; the upstream repository is archived) Affected scope: Distributed erasure only; cluster-root / internode JWT required Prerequisite reading: …

  • Silo 20260618 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260618 Released

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    In Security

    securityReadMultiple

    Featured Image for CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

  • Silo 20260417 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260417 Released

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

  • MinIO Fork, Promise Kept

    In Post

    postminio

    Featured Image for MinIO Fork, Promise Kept

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    In Security

    securityUnsigned Trailer

    Featured Image for CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    In Security

    securitySnowball

    Featured Image for CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    In Security

    securityS3 Select

    Featured Image for CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    securityReplication

    Featured Image for CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    In Security

    securityLDAP STS

    Featured Image for CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    In Security

    securityOIDC

    Featured Image for CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

  • CVE-2026-32285: The jsonparser Advisory That Required No Patch

    In Security

    securityjsonparser

    Featured Image for CVE-2026-32285: The jsonparser Advisory That Required No Patch

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

  • Silo 20260325 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260325 Released

    Published: 2026-03-25 · Version: RELEASE.2026-03-25T00-00-00Z This is a maintenance release centered on packaging, stability, and security disclosure. It improves the shipping artifacts, fixes an LDAP TLS regression, and explicitly documents the …

    Published: 2026-03-25 · Version: RELEASE.2026-03-25T00-00-00Z This is a maintenance release centered on packaging, stability, and security disclosure. It improves the shipping artifacts, fixes an LDAP TLS regression, and explicitly documents the …