CLEANSTART-2026-RC17482
Dashboard / Vulnerabilities / CLEANSTART-2026-RC17482
CLEANSTART-2026-RC17482
Summary: ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
Details: Multiple security vulnerabilities affect the minio-operator package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-RC17482.json, https://osv.dev/vulnerability/CVE-2025-15558, https://osv.dev/vulnerability/CVE-2025-22868, https://osv.dev/vulnerability/CVE-2025-30204, https://osv.dev/vulnerability/CVE-2025-47912, https://osv.dev/vulnerability/CVE-2025-58183, https://osv.dev/vulnerability/CVE-2025-58185, https://osv.dev/vulnerability/CVE-2025-58186, https://osv.dev/vulnerability/CVE-2025-58187, https://osv.dev/vulnerability/CVE-2025-58188, https://osv.dev/vulnerability/CVE-2025-58189, https://osv.dev/vulnerability/CVE-2025-61723, https://osv.dev/vulnerability/CVE-2025-61724, https://osv.dev/vulnerability/CVE-2025-61725, https://osv.dev/vulnerability/CVE-2025-61726, https://osv.dev/vulnerability/CVE-2025-61727, https://osv.dev/vulnerability/CVE-2025-61728, https://osv.dev/vulnerability/CVE-2025-61729, https://osv.dev/vulnerability/CVE-2025-61730, https://osv.dev/vulnerability/CVE-2025-61731, https://osv.dev/vulnerability/CVE-2025-61732, https://osv.dev/vulnerability/CVE-2025-68119, https://osv.dev/vulnerability/CVE-2025-68121, https://osv.dev/vulnerability/CVE-2026-25679, https://osv.dev/vulnerability/CVE-2026-25680, https://osv.dev/vulnerability/CVE-2026-27139, https://osv.dev/vulnerability/CVE-2026-27142, https://osv.dev/vulnerability/CVE-2026-27145, https://osv.dev/vulnerability/CVE-2026-33814, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-39822, https://osv.dev/vulnerability/CVE-2026-39833, https://osv.dev/vulnerability/CVE-2026-39836, https://osv.dev/vulnerability/CVE-2026-42499, https://osv.dev/vulnerability/CVE-2026-42504, https://osv.dev/vulnerability/CVE-2026-42505, https://osv.dev/vulnerability/CVE-2026-42507, https://osv.dev/vulnerability/CVE-2026-42508, https://osv.dev/vulnerability/CVE-2026-46595, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56852, https://osv.dev/vulnerability/CVE-2026-56853, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56859, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/CVE-2026-56862, https://osv.dev/vulnerability/CVE-2026-56864, https://osv.dev/vulnerability/CVE-2026-56865, https://osv.dev/vulnerability/ghsa-259r-337f-4rfw, https://osv.dev/vulnerability/ghsa-6v2p-p543-phr9, https://osv.dev/vulnerability/ghsa-f6x5-jh6r-wrfv, https://osv.dev/vulnerability/ghsa-j5w8-q4qc-rx2x, https://osv.dev/vulnerability/ghsa-p436-gjf2-799p, https://nvd.nist.gov/vuln/detail/CVE-2025-15558, https://nvd.nist.gov/vuln/detail/CVE-2025-22868, https://nvd.nist.gov/vuln/detail/CVE-2025-30204, https://nvd.nist.gov/vuln/detail/CVE-2025-47912, https://nvd.nist.gov/vuln/detail/CVE-2025-58183, https://nvd.nist.gov/vuln/detail/CVE-2025-58185, https://nvd.nist.gov/vuln/detail/CVE-2025-58186, https://nvd.nist.gov/vuln/detail/CVE-2025-58187, https://nvd.nist.gov/vuln/detail/CVE-2025-58188, https://nvd.nist.gov/vuln/detail/CVE-2025-58189, https://nvd.nist.gov/vuln/detail/CVE-2025-61723, https://nvd.nist.gov/vuln/detail/CVE-2025-61724, https://nvd.nist.gov/vuln/detail/CVE-2025-61725, https://nvd.nist.gov/vuln/detail/CVE-2025-61726, https://nvd.nist.gov/vuln/detail/CVE-2025-61727, https://nvd.nist.gov/vuln/detail/CVE-2025-61728, https://nvd.nist.gov/vuln/detail/CVE-2025-61729, https://nvd.nist.gov/vuln/detail/CVE-2025-61730, https://nvd.nist.gov/vuln/detail/CVE-2025-61731, https://nvd.nist.gov/vuln/detail/CVE-2025-61732, https://nvd.nist.gov/vuln/detail/CVE-2025-68119, https://nvd.nist.gov/vuln/detail/CVE-2025-68121, https://nvd.nist.gov/vuln/detail/CVE-2026-25679, https://nvd.nist.gov/vuln/detail/CVE-2026-25680, https://nvd.nist.gov/vuln/detail/CVE-2026-27139, https://nvd.nist.gov/vuln/detail/CVE-2026-27142, https://nvd.nist.gov/vuln/detail/CVE-2026-27145, https://nvd.nist.gov/vuln/detail/CVE-2026-33814, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-39822, https://nvd.nist.gov/vuln/detail/CVE-2026-39833, https://nvd.nist.gov/vuln/detail/CVE-2026-39836, https://nvd.nist.gov/vuln/detail/CVE-2026-42499, https://nvd.nist.gov/vuln/detail/CVE-2026-42504, https://nvd.nist.gov/vuln/detail/CVE-2026-42505, https://nvd.nist.gov/vuln/detail/CVE-2026-42507, https://nvd.nist.gov/vuln/detail/CVE-2026-42508, https://nvd.nist.gov/vuln/detail/CVE-2026-46595, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56852, https://nvd.nist.gov/vuln/detail/CVE-2026-56853, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56859, https://nvd.nist.gov/vuln/detail/CVE-2026-56860, https://nvd.nist.gov/vuln/detail/CVE-2026-56862, https://nvd.nist.gov/vuln/detail/CVE-2026-56864, https://nvd.nist.gov/vuln/detail/CVE-2026-56865
Affected packages
Package
Name: minio-operator
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
