All verified exploits

CVE-2026-33322 OIDC JWT Algorithm Confusion

Deterministic critical MinIO Added cve-verified-cve-2026-33322

Detects MinIO instances vulnerable to JWT algorithm confusion in OIDC authentication. MinIO stores the OIDC client_secret in its public key lookup map keyed by client_id. An attacker who knows the client secret can forge HS256 identity tokens to assume any IAM role including consoleAdmin, gaining full access to all stored objects. Affects all MinIO releases from RELEASE.2022-11-08 through the last open-source release. Update to MinIO AIStor RELEASE.2026-03-17 or later.

Is your app exploitable through CVE-2026-33322?

Scan your domain free