Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/minio/minio
  4. ›
  5. CVE-2026-33322

CVE-2026-33322: MinIO has JWT Algorithm Confusion in OIDC Authentication

March 19, 2026 (updated March 27, 2026)

What kind of vulnerability is it? Who is impacted?

A JWT algorithm confusion vulnerability in MinIO’s OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin.

An attacker with knowledge of the OIDC ClientSecret can:

  • Impersonate any user identity
  • Obtain S3 credentials with any IAM policy, including consoleAdmin
  • Access, modify, or delete any data in the MinIO deployment

The attack is deterministic (100% success rate, no race conditions).

References

  • github.com/advisories/GHSA-5cx5-wh4m-82fh
  • github.com/minio/minio
  • github.com/minio/minio/security/advisories/GHSA-5cx5-wh4m-82fh
  • nvd.nist.gov/vuln/detail/CVE-2026-33322

Code Behaviors & Features

Detect and mitigate CVE-2026-33322 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.0.0-20260212201848-7aac2a2c5b7c

Solution

Unfortunately, there is no solution available yet.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Source file

go/github.com/minio/minio/CVE-2026-33322.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 11 May 2026 00:19:09 +0000.