OpenStack security advisories

Every OSSA and CVE tracked by Stackers Network, newest first — each linked to the official advisory and to our coverage.

52 advisories tracked across the archive.

AdvisorySummaryLatest coverage
OSSA-2026-026 OSSA OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… 2026-07-11
OSSA-2026-025 OSSA OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… 2026-07-11
CVE-2026-54423 CVE OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… 2026-07-11
CVE-2026-44918 CVE OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… 2026-07-11
OSSA-2026-024 OSSA OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… 2026-06-27
CVE-2026-50221 CVE OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… 2026-06-27
OSSA-2026-023 OSSA [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… 2026-06-20
OSSA-2026-022 OSSA [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… 2026-06-20
OSSA-2026-017 OSSA [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… 2026-06-20
CVE-2026-55748 CVE [OSSN-0097 Errata 1] Horizon RC file escaping (CVE-2026-55748). The previously published Horizon RC-file generation issue now has a CVE assigned. (note) 2026-06-20
CVE-2026-54421 CVE [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… 2026-06-20
CVE-2026-46448 CVE [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… 2026-06-20
CVE-2026-46447 CVE [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… 2026-06-20
OSSA-2026-015 OSSA OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-06-13, 2026-05-30
OSSA-2026-016 OSSA OSSA-2026-016 (Neutron tagging policy bypass, CVE pending) — a singular/plural mismatch between the tagging controller's action names and policy rules lets project readers create… 2026-05-30
OSSA-2026-014 OSSA OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… 2026-05-30
CVE-2026-49017 CVE OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… 2026-05-30
CVE-2026-44394 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-43001 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-43000 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-42999 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-42998 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
OSSA-2026-013 OSSA The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
CVE-2026-44919 CVE The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
CVE-2024-47211 CVE The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
OSSA-2026-012 OSSA OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… 2026-05-16
CVE-2026-44916 CVE OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… 2026-05-16
OSSA-2026-011 OSSA OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
OSSA-2026-010 OSSA OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… 2026-05-09
OSSA-2026-009 OSSA OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
CVE-2026-43002 CVE OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
CVE-2026-42997 CVE OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… 2026-05-09
CVE-2026-40214 CVE OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
CVE-2026-40213 CVE OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
CVE-2014-8124 CVE OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
OSSA-2026-008 OSSA OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… 2026-05-02
CVE-2026-42510 CVE OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… 2026-05-02
OSSA-2026-007 OSSA OSSA-2026-007 — Keystone LDAP identity backend does not convert the enabled attribute to boolean (CVE pending). Benedikt Trefzer and Andrew Bogott independently found that when… 2026-04-18
OSSA-2026-006 OSSA OSSA-2026-006 — DOM-based XSS in Skyline Console (CVE pending). The instance console-log viewer rendered untrusted log content into a new browser window via document.write()… 2026-04-11
OSSA-2026-005 OSSA OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… 2026-04-11
CVE-2026-33551 CVE OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… 2026-04-11
OSSA-2026-004 OSSA OSSA-2026-004 (Glance), CVE pending. Brian Rosmaita announced multiple Server-Side Request Forgery (SSRF) vulnerabilities in Glance image import, reported by Hyeongeun Ji (Open… 2026-03-21
OSSA-2026-003 OSSA OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… 2026-03-07
CVE-2026-28370 CVE OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… 2026-03-07
OSSA-2026-002 OSSA OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
CVE-2026-24709 CVE OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
CVE-2026-24708 CVE OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
OSSA-2026-001 OSSA Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… 2026-01-17
CVE-2026-22797 CVE Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… 2026-01-17
OSSA-2025-002 OSSA OSSA-2025-002 — Unauthenticated Keystone access via EC2/S3 token endpoints (CVE pending). Reported by "kay" and announced by Jeremy Stanley on November 4: any deployment exposing… 2025-11-22, 2025-11-08
CVE-2025-65073 CVE OSSA-2025-002 (CVE-2025-65073) re-published with errata. Jeremy Stanley re-issued the Keystone EC2/S3 token endpoint advisory (also on openstack-announce). MITRE assigned… 2025-11-22
CVE-2025-58068 CVE Herve Beraud's eventlet update noted that CVE-2025-58068 (CVSS 6.3) in Eventlet's WSGI parser — enabling HTTP request smuggling — has been fixed in eventlet 0.40 (specific release… 2025-09-06

Advisory IDs link to the official source (security.openstack.org for OSSAs, cve.org for CVEs). Coverage dates link to the weekly issue that discussed each advisory.