OpenStack security advisories
Every OSSA and CVE tracked by Stackers Network, newest first — each linked to the official advisory and to our coverage.
| Advisory | Summary | Latest coverage |
|---|---|---|
| OSSA-2026-037 OSSA | The 2026.2 "Hibiscus" release is in the home stretch: Milestone-3 / feature freeze landed on Thursday August 27, and the mailing lists reflect it — a wave of FFE requests, a… | 2026-09-19, 2026-08-29 |
| OSSA-2026-038 OSSA | OSSA-2026-038 — Multiple SSRF vulnerabilities in Glance (CVE-2026-71196/71197/71198) is the headline item. Glance's web-download import method ships with insecure default… | 2026-09-05 |
| CVE-2026-71196 CVE | OSSA-2026-038 — Multiple SSRF vulnerabilities in Glance (CVE-2026-71196/71197/71198) is the headline item. Glance's web-download import method ships with insecure default… | 2026-09-05 |
| CVE-2026-80184 CVE | OSSA-2026-037 (Keystone, CVE-2026-80182 and CVE-2026-80184) was published August 25 and then re-issued as *errata 1* the same day to fill in the assigned CVE numbers. Grzegorz… | 2026-08-29 |
| CVE-2026-80182 CVE | OSSA-2026-037 (Keystone, CVE-2026-80182 and CVE-2026-80184) was published August 25 and then re-issued as *errata 1* the same day to fill in the assigned CVE numbers. Grzegorz… | 2026-08-29 |
| OSSA-2026-036 OSSA | OSSA-2026-036 — Aodh + Watcher (CVE-2026-76878). Chen YuXiang (ICT, Chinese Academy of Sciences) found that Aodh does not enforce project scope on alarm listing when… | 2026-08-22 |
| OSSA-2026-035 OSSA | [OSSA-2026-035] Octavia — Unauthorized QoS policy deletion lock (CVE pending). Affects Octavia <16.0.2, 17.0.0, 18.0.0; all deployments impacted. An authenticated user can… | 2026-08-22, 2026-08-15 |
| OSSA-2026-008 OSSA | OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… | 2026-08-22, 2026-05-02 |
| CVE-2026-76878 CVE | OSSA-2026-036 — Aodh + Watcher (CVE-2026-76878). Chen YuXiang (ICT, Chinese Academy of Sciences) found that Aodh does not enforce project scope on alarm listing when… | 2026-08-22 |
| CVE-2026-74248 CVE | OSSA-2026-035 — Octavia (CVE-2026-74248). Same reporter: by associating another project's QoS policy with an amphora, an authenticated user can block deletion of that policy. All… | 2026-08-22 |
| CVE-2026-42510 CVE | OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… | 2026-08-22, 2026-05-02 |
| OSSA-2026-034 OSSA | [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… | 2026-08-15 |
| CVE-2026-71194 CVE | [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… | 2026-08-15 |
| CVE-2026-71193 CVE | [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… | 2026-08-15 |
| OSSA-2026-033 OSSA | OSSA-2026-033 — Ironic Portgroup shard filter bypass (CVE-2026-71201). A project reader listing portgroups by shard sees portgroups outside its project. Affects Ironic >=34.0.0… | 2026-08-08 |
| OSSA-2026-031 OSSA | OSSA-2026-031 — Swift proxy DoS via Accept header. Also from Schwede: catastrophic regex backtracking in the Accept header parser lets an unauthenticated attacker exhaust proxy… | 2026-08-08, 2026-08-01 |
| OSSA-2026-030 OSSA | OSSA-2026-030 — Swift S3API header authorization bypass. Two distinct vulnerabilities reported by Christian Schwede (NVIDIA) allow an attacker who knows target container/object… | 2026-08-08, 2026-08-01 |
| OSSA-2026-026 OSSA | OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… | 2026-08-08, 2026-07-11 |
| OSSA-2026-007 OSSA | OSSA-2026-007 — Keystone LDAP identity backend does not convert the enabled attribute to boolean (CVE pending). Benedikt Trefzer and Andrew Bogott independently found that when… | 2026-08-08, 2026-04-18 |
| CVE-2026-71201 CVE | OSSA-2026-033 — Ironic Portgroup shard filter bypass (CVE-2026-71201). A project reader listing portgroups by shard sees portgroups outside its project. Affects Ironic >=34.0.0… | 2026-08-08 |
| CVE-2026-71192 CVE | OSSA-2026-030 errata — Swift S3API authorization bypass (CVE-2026-71191, CVE-2026-71192). Two flaws in S3API header validation let an attacker copy/read cross-tenant objects — one… | 2026-08-08 |
| CVE-2026-71191 CVE | OSSA-2026-030 errata — Swift S3API authorization bypass (CVE-2026-71191, CVE-2026-71192). Two flaws in S3API header validation let an attacker copy/read cross-tenant objects — one… | 2026-08-08 |
| CVE-2026-71190 CVE | OSSA-2026-031 errata — Swift Accept-header ReDoS (CVE-2026-71190). Unauthenticated attackers can exhaust Swift proxy workers via crafted Accept headers. | 2026-08-08 |
| CVE-2026-40683 CVE | OSSA-2026-007 errata — Keystone LDAP enabled misinterpretation (CVE-2026-40683). LDAP-disabled users could still authenticate when user_enabled_invert=False (the default)… | 2026-08-08 |
| OSSA-2026-032 OSSA | OSSA-2026-032 — Neutron subnetpool onboarding cross-project mutation (CVE-2026-55707). Reported by Tim Shephard (roiai.ca): a project member can onboard subnets from *another*… | 2026-08-01 |
| CVE-2026-55707 CVE | OSSA-2026-032 — Neutron subnetpool onboarding cross-project mutation (CVE-2026-55707). Reported by Tim Shephard (roiai.ca): a project member can onboard subnets from *another*… | 2026-08-01 |
| OSSA-2026-029 OSSA | OSSA-2026-029 — Zaqar authentication bypass (CVE-2026-66139). Reported by Chen YuXiang (ICT, CAS). Sending an EXTRA-SPEC header causes Zaqar to skip Keystone authentication… | 2026-07-25 |
| OSSA-2026-028 OSSA | OSSA-2026-028 — IPA credential extraction via malicious container (CVE-2026-54422). Reported by Yuliang Xiao. In the bootc deploy interface, a malicious container can extract the… | 2026-07-25 |
| OSSA-2026-027 OSSA | OSSA-2026-027 — Ironic Python Agent root RCE (CVE-2026-66138). Reported by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) via the Metal3.io Security Team. The ntp_server… | 2026-07-25 |
| CVE-2026-66139 CVE | OSSA-2026-029 — Zaqar authentication bypass (CVE-2026-66139). Reported by Chen YuXiang (ICT, CAS). Sending an EXTRA-SPEC header causes Zaqar to skip Keystone authentication… | 2026-07-25 |
| CVE-2026-66138 CVE | OSSA-2026-027 — Ironic Python Agent root RCE (CVE-2026-66138). Reported by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) via the Metal3.io Security Team. The ntp_server… | 2026-07-25 |
| CVE-2026-54422 CVE | OSSA-2026-028 — IPA credential extraction via malicious container (CVE-2026-54422). Reported by Yuliang Xiao. In the bootc deploy interface, a malicious container can extract the… | 2026-07-25 |
| OSSA-2026-025 OSSA | OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… | 2026-07-11 |
| CVE-2026-54423 CVE | OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… | 2026-07-11 |
| CVE-2026-44918 CVE | OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… | 2026-07-11 |
| OSSA-2026-024 OSSA | OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… | 2026-06-27 |
| CVE-2026-50221 CVE | OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… | 2026-06-27 |
| OSSA-2026-023 OSSA | [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… | 2026-06-20 |
| OSSA-2026-022 OSSA | [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… | 2026-06-20 |
| OSSA-2026-017 OSSA | [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… | 2026-06-20 |
| CVE-2026-55748 CVE | [OSSN-0097 Errata 1] Horizon RC file escaping (CVE-2026-55748). The previously published Horizon RC-file generation issue now has a CVE assigned. (note) | 2026-06-20 |
| CVE-2026-54421 CVE | [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… | 2026-06-20 |
| CVE-2026-46448 CVE | [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… | 2026-06-20 |
| CVE-2026-46447 CVE | [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… | 2026-06-20 |
| OSSA-2026-015 OSSA | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-06-13, 2026-05-30 |
| OSSA-2026-016 OSSA | OSSA-2026-016 (Neutron tagging policy bypass, CVE pending) — a singular/plural mismatch between the tagging controller's action names and policy rules lets project readers create… | 2026-05-30 |
| OSSA-2026-014 OSSA | OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… | 2026-05-30 |
| CVE-2026-49017 CVE | OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… | 2026-05-30 |
| CVE-2026-44394 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-43001 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-43000 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-42999 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-42998 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| OSSA-2026-013 OSSA | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| CVE-2026-44919 CVE | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| CVE-2024-47211 CVE | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| OSSA-2026-012 OSSA | OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… | 2026-05-16 |
| CVE-2026-44916 CVE | OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… | 2026-05-16 |
| OSSA-2026-011 OSSA | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| OSSA-2026-010 OSSA | OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… | 2026-05-09 |
| OSSA-2026-009 OSSA | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| CVE-2026-43002 CVE | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| CVE-2026-42997 CVE | OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… | 2026-05-09 |
| CVE-2026-40214 CVE | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| CVE-2026-40213 CVE | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| CVE-2014-8124 CVE | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| OSSA-2026-006 OSSA | OSSA-2026-006 — DOM-based XSS in Skyline Console (CVE pending). The instance console-log viewer rendered untrusted log content into a new browser window via document.write()… | 2026-04-11 |
| OSSA-2026-005 OSSA | OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… | 2026-04-11 |
| CVE-2026-33551 CVE | OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… | 2026-04-11 |
| OSSA-2026-004 OSSA | OSSA-2026-004 (Glance), CVE pending. Brian Rosmaita announced multiple Server-Side Request Forgery (SSRF) vulnerabilities in Glance image import, reported by Hyeongeun Ji (Open… | 2026-03-21 |
| OSSA-2026-003 OSSA | OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… | 2026-03-07 |
| CVE-2026-28370 CVE | OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… | 2026-03-07 |
| OSSA-2026-002 OSSA | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| CVE-2026-24709 CVE | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| CVE-2026-24708 CVE | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| OSSA-2026-001 OSSA | Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… | 2026-01-17 |
| CVE-2026-22797 CVE | Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… | 2026-01-17 |
| OSSA-2025-002 OSSA | OSSA-2025-002 — Unauthenticated Keystone access via EC2/S3 token endpoints (CVE pending). Reported by "kay" and announced by Jeremy Stanley on November 4: any deployment exposing… | 2025-11-22, 2025-11-08 |
| CVE-2025-65073 CVE | OSSA-2025-002 (CVE-2025-65073) re-published with errata. Jeremy Stanley re-issued the Keystone EC2/S3 token endpoint advisory (also on openstack-announce). MITRE assigned… | 2025-11-22 |
| CVE-2025-58068 CVE | Herve Beraud's eventlet update noted that CVE-2025-58068 (CVSS 6.3) in Eventlet's WSGI parser — enabling HTTP request smuggling — has been fixed in eventlet 0.40 (specific release… | 2025-09-06 |
Advisory IDs link to the official source (security.openstack.org for OSSAs, cve.org for CVEs). Coverage dates link to the weekly issue that discussed each advisory.