OpenStack security advisories
Every OSSA and CVE tracked by Stackers Network, newest first — each linked to the official advisory and to our coverage.
| Advisory | Summary | Latest coverage |
|---|---|---|
| OSSA-2026-026 OSSA | OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… | 2026-07-11 |
| OSSA-2026-025 OSSA | OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… | 2026-07-11 |
| CVE-2026-54423 CVE | OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… | 2026-07-11 |
| CVE-2026-44918 CVE | OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… | 2026-07-11 |
| OSSA-2026-024 OSSA | OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… | 2026-06-27 |
| CVE-2026-50221 CVE | OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… | 2026-06-27 |
| OSSA-2026-023 OSSA | [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… | 2026-06-20 |
| OSSA-2026-022 OSSA | [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… | 2026-06-20 |
| OSSA-2026-017 OSSA | [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… | 2026-06-20 |
| CVE-2026-55748 CVE | [OSSN-0097 Errata 1] Horizon RC file escaping (CVE-2026-55748). The previously published Horizon RC-file generation issue now has a CVE assigned. (note) | 2026-06-20 |
| CVE-2026-54421 CVE | [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… | 2026-06-20 |
| CVE-2026-46448 CVE | [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… | 2026-06-20 |
| CVE-2026-46447 CVE | [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… | 2026-06-20 |
| OSSA-2026-015 OSSA | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-06-13, 2026-05-30 |
| OSSA-2026-016 OSSA | OSSA-2026-016 (Neutron tagging policy bypass, CVE pending) — a singular/plural mismatch between the tagging controller's action names and policy rules lets project readers create… | 2026-05-30 |
| OSSA-2026-014 OSSA | OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… | 2026-05-30 |
| CVE-2026-49017 CVE | OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… | 2026-05-30 |
| CVE-2026-44394 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-43001 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-43000 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-42999 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| CVE-2026-42998 CVE | OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… | 2026-05-30 |
| OSSA-2026-013 OSSA | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| CVE-2026-44919 CVE | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| CVE-2024-47211 CVE | The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… | 2026-05-23 |
| OSSA-2026-012 OSSA | OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… | 2026-05-16 |
| CVE-2026-44916 CVE | OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… | 2026-05-16 |
| OSSA-2026-011 OSSA | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| OSSA-2026-010 OSSA | OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… | 2026-05-09 |
| OSSA-2026-009 OSSA | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| CVE-2026-43002 CVE | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| CVE-2026-42997 CVE | OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… | 2026-05-09 |
| CVE-2026-40214 CVE | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| CVE-2026-40213 CVE | OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… | 2026-05-09 |
| CVE-2014-8124 CVE | OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… | 2026-05-09 |
| OSSA-2026-008 OSSA | OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… | 2026-05-02 |
| CVE-2026-42510 CVE | OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… | 2026-05-02 |
| OSSA-2026-007 OSSA | OSSA-2026-007 — Keystone LDAP identity backend does not convert the enabled attribute to boolean (CVE pending). Benedikt Trefzer and Andrew Bogott independently found that when… | 2026-04-18 |
| OSSA-2026-006 OSSA | OSSA-2026-006 — DOM-based XSS in Skyline Console (CVE pending). The instance console-log viewer rendered untrusted log content into a new browser window via document.write()… | 2026-04-11 |
| OSSA-2026-005 OSSA | OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… | 2026-04-11 |
| CVE-2026-33551 CVE | OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… | 2026-04-11 |
| OSSA-2026-004 OSSA | OSSA-2026-004 (Glance), CVE pending. Brian Rosmaita announced multiple Server-Side Request Forgery (SSRF) vulnerabilities in Glance image import, reported by Hyeongeun Ji (Open… | 2026-03-21 |
| OSSA-2026-003 OSSA | OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… | 2026-03-07 |
| CVE-2026-28370 CVE | OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… | 2026-03-07 |
| OSSA-2026-002 OSSA | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| CVE-2026-24709 CVE | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| CVE-2026-24708 CVE | OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… | 2026-02-21 |
| OSSA-2026-001 OSSA | Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… | 2026-01-17 |
| CVE-2026-22797 CVE | Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… | 2026-01-17 |
| OSSA-2025-002 OSSA | OSSA-2025-002 — Unauthenticated Keystone access via EC2/S3 token endpoints (CVE pending). Reported by "kay" and announced by Jeremy Stanley on November 4: any deployment exposing… | 2025-11-22, 2025-11-08 |
| CVE-2025-65073 CVE | OSSA-2025-002 (CVE-2025-65073) re-published with errata. Jeremy Stanley re-issued the Keystone EC2/S3 token endpoint advisory (also on openstack-announce). MITRE assigned… | 2025-11-22 |
| CVE-2025-58068 CVE | Herve Beraud's eventlet update noted that CVE-2025-58068 (CVSS 6.3) in Eventlet's WSGI parser — enabling HTTP request smuggling — has been fixed in eventlet 0.40 (specific release… | 2025-09-06 |
Advisory IDs link to the official source (security.openstack.org for OSSAs, cve.org for CVEs). Coverage dates link to the weekly issue that discussed each advisory.