#VU117707 Input validation error in minio-java - CVE-2025-59952
Published: October 28, 2025
minio-java
MinIO
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application automatically substitutes XML tag values containing references to system properties or environment variables. A remote attacker can pass a specially crafted XML file to the application and obtain sensitive information.