Use of a Broken or Risky Cryptographic Algorithm Affecting github.com/minio/minio/internal/config/identity/openid package, versions >=RELEASE.2022-11-08T05-27-07Z


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.41% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use of a Broken or Risky Cryptographic Algorithm vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMMINIOMINIOINTERNALCONFIGIDENTITYOPENID-15701708
  • published20 Mar 2026
  • disclosed19 Mar 2026
  • creditSang-Hoon Choi

Introduced: 19 Mar 2026

CVE-2026-33322  (opens in a new tab)
CWE-327  (opens in a new tab)

How to fix?

There is no fixed version for github.com/minio/minio/internal/config/identity/openid.

Overview

Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm in the OpenID Connect authentication. An attacker can impersonate any user and obtain unauthorized S3 credentials with any policy, including administrative privileges, by forging identity tokens if they possess the OIDC ClientSecret.

Workaround

This vulnerability can be mitigated by ensuring that the OIDC ClientSecret is treated as a highly sensitive credential and is not exposed to untrusted parties.

The vendor patched this issue MinIO AIStor RELEASE.2026-03-17T21-25-16Z. Upgrade guide.

References

CVSS Base Scores

version 4.0
version 3.1