Vulnerabilities in OpenStack

66 results
Vexday analysis

OpenStack apresenta 43 vulnerabilidades registradas, com concentração crítica em autorização e controle de acesso (CWE-863); 30 foram publicadas nos últimos 90 dias, indicando risco em evolução constante. Embora nenhuma esteja sob ataque ativo documentado (KEV), o volume recente de divulgações e apenas 3 críticas sugerem um panorama de médio risco operacional que requer monitoramento contínuo de atualizações.

CVE-2026-42998MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that EPSS 0.4%CVE-2026-80183HIGHIn OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignmentEPSS 0.4%CVE-2026-24708HIGHAn issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a rooEPSS 0.4%CVE-2026-50266LOWIn OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set devicEPSS 0.4%CVE-2026-40683HIGHIn OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enableEPSS 0.4%CVE-2026-93852HIGHIn OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing projecEPSS 0.4%CVE-2026-49017HIGHIn OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request boEPSS 0.4%CVE-2026-44916LOWIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.4%CVE-2026-40214MEDIUMIn OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column EPSS 0.3%CVE-2026-40213HIGHOpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorEPSS 0.3%CVE-2026-33551LOWAn issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials caEPSS 0.3%CVE-2026-90461MEDIUMOpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) BEPSS 0.3%CVE-2026-74248MEDIUMOpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with EPSS 0.3%CVE-2026-44394MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the originaEPSS 0.3%CVE-2026-40212MEDIUMOpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.wrEPSS 0.3%CVE-2026-74250MEDIUMIn OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing tEPSS 0.3%CVE-2026-77648LOWIn OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetcEPSS 0.3%CVE-2017-12155—A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as worldEPSS 0.3%CVE-2026-71201MEDIUMIn OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned orEPSS 0.3%CVE-2026-97404CRITICALIn OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature headeEPSS 0.3%