Skip to content

PGSTY SILO Blog

  • Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    In Security

    SecurityMultipart Upload

    Featured Image for Sorted Is Not Increasing: How One Duplicate Part Number Doubled an Object

    Status: Fixed on the local pgsty/minio branch as 22c1e41fd, unreleased Classification: Data correctness, not a vulnerability — see Why this is not a CVE Affected scope: All backends, any authenticated S3 client, on its own upload Tracking: …

    Status: Fixed on the local pgsty/minio branch as 22c1e41fd, unreleased Classification: Data correctness, not a vulnerability — see Why this is not a CVE Affected scope: All backends, any authenticated S3 client, on its own upload Tracking: …

  • Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    In Security

    SecurityPath Containment

    Featured Image for Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing

    Status: Fixed on the local pgsty/minio branch, unreleased and not disclosed (no CVE/GHSA requested; the upstream repository is archived) Affected scope: Distributed erasure only; cluster-root / internode JWT required Prerequisite reading: …

    Status: Fixed on the local pgsty/minio branch, unreleased and not disclosed (no CVE/GHSA requested; the upstream repository is archived) Affected scope: Distributed erasure only; cluster-root / internode JWT required Prerequisite reading: …

  • Silo 20260618 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260618 Released

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

    Published: 2026-06-18 · Version: RELEASE.2026-06-18T00-00-00Z This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the …

  • CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    In Security

    SecurityReadMultiple

    Featured Image for CVE-2026-42600: ReadMultiple Storage-REST Path Traversal

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

    Status: Released First containing release: RELEASE.2026-06-18T00-00-00Z GitHub advisory: GHSA-xh8f-g2qw-gcm7 Affected scope: Distributed erasure only; cluster-root / internode JWT required The msgpack body of /rmpl carried Bucket, Prefix, and Files. …

  • Silo 20260417 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260417 Released

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

    Published: 2026-04-17 · Version: RELEASE.2026-04-17T00-00-00Z This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the …

  • MinIO Fork, Promise Kept

    In Post

    postminio

    Featured Image for MinIO Fork, Promise Kept

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …

    Two months ago in “MinIO is Dead, Long Live MinIO,” I promised I’d keep the MinIO fork patched. The recurring objection on HN is fair: can one person actually maintain something like this? The real answer isn’t clicking fork. It’s what happens when …

  • CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    In Security

    SecurityUnsigned Trailer

    Featured Image for CVE-2026-41145: Unsigned-Trailer Query Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-hv4r-mvr4-25vw Query-string SigV4 credentials could enter a STREAMING-UNSIGNED-PAYLOAD-TRAILER data flow, while the old code verified the signature only …

  • CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    In Security

    SecuritySnowball

    Featured Image for CVE-2026-40344: Snowball Auto-Extract Authentication Bypass

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub advisory: GHSA-9c4q-hq6p-c237 Snowball’s PutObjectExtractHandler omitted the streaming unsigned-trailer authentication case. A tar stream with a forged signature could …

  • CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    In Security

    SecurityS3 Select

    Featured Image for CVE-2026-39414: Oversized S3 Select Records and a SIMD Bypass

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

    Status: Released; the second-round fix was completed in June Initial fix release: RELEASE.2026-04-17T00-00-00Z Complete fix release: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#25 The first fix in April reused the existing 1 MiB …

  • CVE-2026-34204: Replication Metadata Injection

    In Security

    SecurityReplication

    Featured Image for CVE-2026-34204: Replication Metadata Injection

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z GitHub issue: pgsty/minio#24 Ordinary PUT and COPY requests could smuggle X-Minio-Replication-* headers into internal X-Minio-Internal-* SSE metadata, creating objects whose …

  • CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    In Security

    SecurityLDAP STS

    Featured Image for CVE-2026-33419: LDAP STS Enumeration and the Throttling Chain

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

    Status: Released, followed by two rounds of corrections First containing release: RELEASE.2026-04-17T00-00-00Z Complete correction: RELEASE.2026-06-18T00-00-00Z GitHub issue: pgsty/minio#23 The core vulnerability was straightforward: LDAP STS …

  • CVE-2026-33322: OIDC JWT Algorithm Confusion

    In Security

    SecurityOIDC

    Featured Image for CVE-2026-33322: OIDC JWT Algorithm Confusion

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

    Status: Released First containing release: RELEASE.2026-04-17T00-00-00Z Affected entry points: AssumeRoleWithWebIdentity, AssumeRoleWithClientGrants GitHub issue: pgsty/minio#22 The old implementation placed the OIDC client secret in the JWT verifier …

  • CVE-2026-32285: The jsonparser Advisory That Required No Patch

    In Security

    Securityjsonparser

    Featured Image for CVE-2026-32285: The jsonparser Advisory That Required No Patch

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

    Status: Closed without a code change GitHub issue: pgsty/minio#26 Security maintenance is not always a sequence of “find a vulnerability, then ship a patch.” The initial assessment of CVE-2026-32285 was that the repository might still carry a …

  • Silo 20260325 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260325 Released

    Published: 2026-03-25 · Version: RELEASE.2026-03-25T00-00-00Z This is a maintenance release centered on packaging, stability, and security disclosure. It improves the shipping artifacts, fixes an LDAP TLS regression, and explicitly documents the …

    Published: 2026-03-25 · Version: RELEASE.2026-03-25T00-00-00Z This is a maintenance release centered on packaging, stability, and security disclosure. It improves the shipping artifacts, fixes an LDAP TLS regression, and explicitly documents the …

  • Silo 20260321 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260321 Released

    Published: 2026-03-21 · Version: RELEASE.2026-03-21T00-00-00Z This maintenance release is built around the Go 1.26.1 upgrade and a broad dependency refresh. Beyond stricter compiler and linter compatibility fixes, it also delivers the most …

    Published: 2026-03-21 · Version: RELEASE.2026-03-21T00-00-00Z This maintenance release is built around the Go 1.26.1 upgrade and a broad dependency refresh. Beyond stricter compiler and linter compatibility fixes, it also delivers the most …

  • Silo 20260314 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260314 Released

    Published: 2026-03-14 · Version: RELEASE.2026-03-14T12-00-00Z This release switches the project to the community-maintained Console fork and performs a sizeable dependency refresh to establish the base for the later Go 1.26.x maintenance releases. …

    Published: 2026-03-14 · Version: RELEASE.2026-03-14T12-00-00Z This release switches the project to the community-maintained Console fork and performs a sizeable dependency refresh to establish the base for the later Go 1.26.x maintenance releases. …

  • Silo 20260214 Released

    In Release

    Releasesilo

    Featured Image for Silo 20260214 Released

    Published: 2026-02-14 · Version: RELEASE.2026-02-14T12-00-00Z This early infrastructure-focused community release restores the embedded Console, introduces GitHub CI/CD, and lifts the Go baseline to 1.26.0, which also absorbs a batch of security …

    Published: 2026-02-14 · Version: RELEASE.2026-02-14T12-00-00Z This early infrastructure-focused community release restores the embedded Console, introduces GitHub CI/CD, and lifts the Go baseline to 1.26.0, which also absorbs a batch of security …

  • MinIO Is Dead, Long Live MinIO

    In Post

    postminio

    Featured Image for MinIO Is Dead, Long Live MinIO

    MinIO’s open-source repo has been officially archived. No more maintenance. End of an era — but open source doesn’t die that easily. I created a MinIO fork, restored the admin console, rebuilt the binary distribution pipeline, and brought it back to …

    MinIO’s open-source repo has been officially archived. No more maintenance. End of an era — but open source doesn’t die that easily. I created a MinIO fork, restored the admin console, rebuilt the binary distribution pipeline, and brought it back to …

  • Silo 20251203 Released

    In Release

    Releasesilo

    Featured Image for Silo 20251203 Released

    Published: 2025-12-15 · Version: RELEASE.2025-12-03T12-00-00Z This is the earliest traceable community release. Its purpose is to establish the community packaging and distribution baseline rather than to deliver incremental fixes over an earlier …

    Published: 2025-12-15 · Version: RELEASE.2025-12-03T12-00-00Z This is the earliest traceable community release. Its purpose is to establish the community packaging and distribution baseline rather than to deliver incremental fixes over an earlier …

  • MinIO Is Dead. Which Next?

    In Post

    postminio

    Featured Image for MinIO Is Dead. Which Next?

    MinIO announced maintenance mode two days ago. I ranted in “MinIO Is Dead” and immediately got flooded with “so what now?” The usual suspects: Ceph, RustFS, SeaweedFS, Garage. I packaged all of them for Linux (RPM/DEB) and ran them through the …

    MinIO announced maintenance mode two days ago. I ranted in “MinIO Is Dead” and immediately got flooded with “so what now?” The usual suspects: Ceph, RustFS, SeaweedFS, Garage. I packaged all of them for Linux (RPM/DEB) and ran them through the …