← Volver al buscador de CVEs

CVE-2026-39414

MinIO

Descripción

MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO-s S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader-s nextSplit() function calls bufio.Reader.ReadBytes(- -) with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.

CVSS 6.5EPSS 0.485%Riesgo 0.68
Ver fuente
Publicación
2026-04-08 21:16:58
Versiones afectadas
cannotmatch
Tipo
Core software
Última modificación
2026-07-24 21:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H