Vulnerabilities in OpenStack

66 results
Vexday analysis

OpenStack apresenta 43 vulnerabilidades registradas, com concentração crítica em autorização e controle de acesso (CWE-863); 30 foram publicadas nos últimos 90 dias, indicando risco em evolução constante. Embora nenhuma esteja sob ataque ativo documentado (KEV), o volume recente de divulgações e apenas 3 críticas sugerem um panorama de médio risco operacional que requer monitoramento contínuo de atualizações.

CVE-2026-43003HIGHAn issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install froEPSS 1.1%CVE-2013-2255—HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-sideEPSS 1.0%CVE-2026-41283CRITICALOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code executiEPSS 0.9%CVE-2026-48681MEDIUMOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.9%CVE-2026-71190HIGHIn OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtrackiEPSS 0.8%CVE-2026-28370CRITICALIn the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger codEPSS 0.8%CVE-2026-66138HIGHIn OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a runniEPSS 0.8%CVE-2026-42510MEDIUMOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.7%CVE-2026-50589MEDIUMIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JEPSS 0.7%CVE-2026-22797CRITICALAn issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1EPSS 0.7%CVE-2026-80184HIGHIn OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials,EPSS 0.6%CVE-2026-43002MEDIUMAn issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before aEPSS 0.6%CVE-2022-38065HIGHA privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissivEPSS 0.6%CVE-2026-43001HIGHAn issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for aEPSS 0.6%CVE-2026-80182HIGHIn OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could cEPSS 0.6%CVE-2026-44919MEDIUMIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///EPSS 0.6%CVE-2026-90460HIGHAn issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, applicatEPSS 0.6%CVE-2026-42997HIGHAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be senEPSS 0.5%CVE-2026-76878HIGHIn OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API EPSS 0.5%CVE-2026-94571CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirectEPSS 0.5%