Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5cx5-wh4m-82fh | MinIO has JWT Algorithm Confusion in OIDC Authentication |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Minio
Minio minio |
|
| Vendors & Products |
Minio
Minio minio |
Tue, 24 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z. | |
| Title | MinIO: JWT Algorithm Confusion in OIDC Authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T14:28:14.561Z
Reserved: 2026-03-18T21:23:36.677Z
Link: CVE-2026-33322
Updated: 2026-03-25T14:00:25.744Z
Status : Awaiting Analysis
Published: 2026-03-24T20:16:27.857
Modified: 2026-03-25T15:41:58.280
Link: CVE-2026-33322
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:57:50Z
Github GHSA