XML Injection Affecting io.minio:minio package, versions [7.0.0,8.6.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.11% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about XML Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-IOMINIO-13147656
  • published30 Sept 2025
  • disclosed29 Sept 2025
  • creditPierre-Yves Guerder, Sopalinge

Introduced: 29 Sep 2025

NewCVE-2025-59952  (opens in a new tab)
CWE-91  (opens in a new tab)

How to fix?

Upgrade io.minio:minio to version 8.6.0 or higher.

Overview

Affected versions of this package are vulnerable to XML Injection when processing XML data with tags containing references to system properties or environment variables. An attacker can access sensitive information, such as credentials, file paths, or system configuration details, by submitting malicious input including such references.

References

CVSS Base Scores

version 4.0
version 3.1