
Replication-header injection can permanently brick MinIO S3 objects
CVE-2026-34204 lets authenticated MinIO clients with `s3:PutObject` permission make objects permanently unreadable by injecting internal SSE metadata via crafted `X-Minio-Replication-*` headers.
NewsCloudStorage
2 minYesterday

