Search CVE reports


Toggle filters

1 – 10 of 24 results


CVE-2026-71192

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71191

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71190

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-50221

Medium priority
Needs evaluation

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49017

Medium priority
Vulnerable

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Vulnerable Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-65073

Medium priority

Some fixes available 9 of 23

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

3 affected packages

swift, heat, keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Not affected Fixed Fixed Needs evaluation Needs evaluation
heat Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
keystone Fixed Fixed Fixed Ignored Ignored
Show less packages

CVE-2022-47950

Medium priority

Some fixes available 10 of 11

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server,...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2017-8761

Low priority
Vulnerable

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2013-7109

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2013-2255

Low priority
Ignored

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

6 affected packages

cinder, keystone, nova, python-keystoneclient, quantum, swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cinder
keystone
nova
python-keystoneclient
quantum
swift
Show less packages