Vulnerabilidades em OpenStack
65 resultadosAnálise Vexday
OpenStack apresenta 43 vulnerabilidades registradas, com concentração crítica em autorização e controle de acesso (CWE-863); 30 foram publicadas nos últimos 90 dias, indicando risco em evolução constante. Embora nenhuma esteja sob ataque ativo documentado (KEV), o volume recente de divulgações e apenas 3 críticas sugerem um panorama de médio risco operacional que requer monitoramento contínuo de atualizações.
CVE-2026-71193CRITICALIn OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to EPSS 0.4%CVE-2026-43002MEDIUMAn issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before aEPSS 0.4%CVE-2026-40683HIGHIn OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enableEPSS 0.3%CVE-2026-90460HIGHAn issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, applicatEPSS 0.3%CVE-2026-44916LOWIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.3%CVE-2026-94571CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirectEPSS 0.3%CVE-2026-94572CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control charactEPSS 0.3%CVE-2026-42999MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raEPSS 0.3%CVE-2026-66139MEDIUMOpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.EPSS 0.3%CVE-2026-43000MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an atEPSS 0.3%CVE-2026-49017HIGHIn OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request boEPSS 0.3%CVE-2026-71194MEDIUMIn OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When tEPSS 0.3%CVE-2026-42998MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that EPSS 0.3%CVE-2026-54423HIGHIn OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use tEPSS 0.3%CVE-2026-49299MEDIUMIn OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defiEPSS 0.3%CVE-2026-71192MEDIUMIn OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) frEPSS 0.3%CVE-2026-54421MEDIUMIn OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can returnEPSS 0.3%CVE-2017-12155—A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as worldEPSS 0.3%CVE-2026-71191MEDIUMIn OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on preEPSS 0.3%CVE-2026-55707HIGHIn OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user canEPSS 0.3%