CVE-2025-59952 - CVE House
Back to Database
Status published High CVE-2025-59952

minio-java Client XML Tag is Vulnerable to Value Substitution

Vulnerability Description

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59952

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

minio-java
Vulnerable Versions:
< 8.6.0

Timeline

Official Publish: September 29th, 2025
Last Modified: January 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)