Vulnerabilities in OpenStack

66 results
Vexday analysis

OpenStack apresenta 43 vulnerabilidades registradas, com concentração crítica em autorização e controle de acesso (CWE-863); 30 foram publicadas nos últimos 90 dias, indicando risco em evolução constante. Embora nenhuma esteja sob ataque ativo documentado (KEV), o volume recente de divulgações e apenas 3 críticas sugerem um panorama de médio risco operacional que requer monitoramento contínuo de atualizações.

CVE-2026-94572CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control charactEPSS 0.5%CVE-2026-71193CRITICALIn OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to EPSS 0.5%CVE-2026-71194MEDIUMIn OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When tEPSS 0.5%CVE-2026-54423HIGHIn OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use tEPSS 0.5%CVE-2026-66139MEDIUMOpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.EPSS 0.5%CVE-2026-44917MEDIUMOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pEPSS 0.5%CVE-2026-54421MEDIUMIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can returnEPSS 0.5%CVE-2026-55748MEDIUMOpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharaEPSS 0.5%CVE-2026-46448MEDIUMIn OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.EPSS 0.5%CVE-2026-71198HIGHIn OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike theEPSS 0.4%CVE-2026-71192MEDIUMIn OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) frEPSS 0.4%CVE-2026-34881MEDIUMOpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, EPSS 0.4%CVE-2026-46447MEDIUMOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_infoEPSS 0.4%CVE-2026-55707HIGHIn OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user canEPSS 0.4%CVE-2026-49299MEDIUMIn OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defiEPSS 0.4%CVE-2026-43000MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an atEPSS 0.4%CVE-2026-42999MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raEPSS 0.4%CVE-2026-71191MEDIUMIn OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on preEPSS 0.4%CVE-2026-44918MEDIUMOpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.EPSS 0.4%CVE-2026-93854HIGHIn OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2EPSS 0.4%