CVE-2025-59952
HIGHMinIO Java SDK < 8.6.0 - Information Exposure via XML System Property Substitution
Title source: llmDescription
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/minio/minio-java/security/advisories/GHSA-h7rh-xfpj-hpcm
Patch x_refsource_misc
https://github.com/minio/minio-java/commit/f7a98d06b25e5464bdd4811b044e25ff9101d37f
Release Notes x_refsource_misc
https://github.com/minio/minio-java/releases/tag/8.6.0
Scores
CVSS v4
8.7
EPSS
0.0046
EPSS Percentile
36.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
CWE-94
Status
published
Products (2)
io.minio/minio
0 - 8.6.0Maven
minio/minio-java
< 8.6.0
Published
Sep 30, 2025
Tracked Since
Feb 18, 2026