OpenStack security advisories

Every OSSA and CVE tracked by Stackers Network, newest first — each linked to the official advisory and to our coverage.

80 advisories tracked across the archive.

AdvisorySummaryLatest coverage
OSSA-2026-037 OSSA The 2026.2 "Hibiscus" release is in the home stretch: Milestone-3 / feature freeze landed on Thursday August 27, and the mailing lists reflect it — a wave of FFE requests, a… 2026-09-19, 2026-08-29
OSSA-2026-038 OSSA OSSA-2026-038 — Multiple SSRF vulnerabilities in Glance (CVE-2026-71196/71197/71198) is the headline item. Glance's web-download import method ships with insecure default… 2026-09-05
CVE-2026-71196 CVE OSSA-2026-038 — Multiple SSRF vulnerabilities in Glance (CVE-2026-71196/71197/71198) is the headline item. Glance's web-download import method ships with insecure default… 2026-09-05
CVE-2026-80184 CVE OSSA-2026-037 (Keystone, CVE-2026-80182 and CVE-2026-80184) was published August 25 and then re-issued as *errata 1* the same day to fill in the assigned CVE numbers. Grzegorz… 2026-08-29
CVE-2026-80182 CVE OSSA-2026-037 (Keystone, CVE-2026-80182 and CVE-2026-80184) was published August 25 and then re-issued as *errata 1* the same day to fill in the assigned CVE numbers. Grzegorz… 2026-08-29
OSSA-2026-036 OSSA OSSA-2026-036 — Aodh + Watcher (CVE-2026-76878). Chen YuXiang (ICT, Chinese Academy of Sciences) found that Aodh does not enforce project scope on alarm listing when… 2026-08-22
OSSA-2026-035 OSSA [OSSA-2026-035] Octavia — Unauthorized QoS policy deletion lock (CVE pending). Affects Octavia <16.0.2, 17.0.0, 18.0.0; all deployments impacted. An authenticated user can… 2026-08-22, 2026-08-15
OSSA-2026-008 OSSA OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… 2026-08-22, 2026-05-02
CVE-2026-76878 CVE OSSA-2026-036 — Aodh + Watcher (CVE-2026-76878). Chen YuXiang (ICT, Chinese Academy of Sciences) found that Aodh does not enforce project scope on alarm listing when… 2026-08-22
CVE-2026-74248 CVE OSSA-2026-035 — Octavia (CVE-2026-74248). Same reporter: by associating another project's QoS policy with an amphora, an authenticated user can block deletion of that policy. All… 2026-08-22
CVE-2026-42510 CVE OSSA-2026-008 (errata 1) / CVE-2026-42510 — Command injection in Ironic IPMI console implementations. The advisory was initially published 27 April without a CVE; CVE-2026-42510… 2026-08-22, 2026-05-02
OSSA-2026-034 OSSA [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… 2026-08-15
CVE-2026-71194 CVE [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… 2026-08-15
CVE-2026-71193 CVE [OSSA-2026-034] Designate — Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling (CVE-2026-71193, CVE-2026-71194). Affects Designate >=1.0.0 <20.0.2, 21.0.0, 22.0.0. Any… 2026-08-15
OSSA-2026-033 OSSA OSSA-2026-033 — Ironic Portgroup shard filter bypass (CVE-2026-71201). A project reader listing portgroups by shard sees portgroups outside its project. Affects Ironic >=34.0.0… 2026-08-08
OSSA-2026-031 OSSA OSSA-2026-031 — Swift proxy DoS via Accept header. Also from Schwede: catastrophic regex backtracking in the Accept header parser lets an unauthenticated attacker exhaust proxy… 2026-08-08, 2026-08-01
OSSA-2026-030 OSSA OSSA-2026-030 — Swift S3API header authorization bypass. Two distinct vulnerabilities reported by Christian Schwede (NVIDIA) allow an attacker who knows target container/object… 2026-08-08, 2026-08-01
OSSA-2026-026 OSSA OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… 2026-08-08, 2026-07-11
OSSA-2026-007 OSSA OSSA-2026-007 — Keystone LDAP identity backend does not convert the enabled attribute to boolean (CVE pending). Benedikt Trefzer and Andrew Bogott independently found that when… 2026-08-08, 2026-04-18
CVE-2026-71201 CVE OSSA-2026-033 — Ironic Portgroup shard filter bypass (CVE-2026-71201). A project reader listing portgroups by shard sees portgroups outside its project. Affects Ironic >=34.0.0… 2026-08-08
CVE-2026-71192 CVE OSSA-2026-030 errata — Swift S3API authorization bypass (CVE-2026-71191, CVE-2026-71192). Two flaws in S3API header validation let an attacker copy/read cross-tenant objects — one… 2026-08-08
CVE-2026-71191 CVE OSSA-2026-030 errata — Swift S3API authorization bypass (CVE-2026-71191, CVE-2026-71192). Two flaws in S3API header validation let an attacker copy/read cross-tenant objects — one… 2026-08-08
CVE-2026-71190 CVE OSSA-2026-031 errata — Swift Accept-header ReDoS (CVE-2026-71190). Unauthenticated attackers can exhaust Swift proxy workers via crafted Accept headers. 2026-08-08
CVE-2026-40683 CVE OSSA-2026-007 errata — Keystone LDAP enabled misinterpretation (CVE-2026-40683). LDAP-disabled users could still authenticate when user_enabled_invert=False (the default)… 2026-08-08
OSSA-2026-032 OSSA OSSA-2026-032 — Neutron subnetpool onboarding cross-project mutation (CVE-2026-55707). Reported by Tim Shephard (roiai.ca): a project member can onboard subnets from *another*… 2026-08-01
CVE-2026-55707 CVE OSSA-2026-032 — Neutron subnetpool onboarding cross-project mutation (CVE-2026-55707). Reported by Tim Shephard (roiai.ca): a project member can onboard subnets from *another*… 2026-08-01
OSSA-2026-029 OSSA OSSA-2026-029 — Zaqar authentication bypass (CVE-2026-66139). Reported by Chen YuXiang (ICT, CAS). Sending an EXTRA-SPEC header causes Zaqar to skip Keystone authentication… 2026-07-25
OSSA-2026-028 OSSA OSSA-2026-028 — IPA credential extraction via malicious container (CVE-2026-54422). Reported by Yuliang Xiao. In the bootc deploy interface, a malicious container can extract the… 2026-07-25
OSSA-2026-027 OSSA OSSA-2026-027 — Ironic Python Agent root RCE (CVE-2026-66138). Reported by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) via the Metal3.io Security Team. The ntp_server… 2026-07-25
CVE-2026-66139 CVE OSSA-2026-029 — Zaqar authentication bypass (CVE-2026-66139). Reported by Chen YuXiang (ICT, CAS). Sending an EXTRA-SPEC header causes Zaqar to skip Keystone authentication… 2026-07-25
CVE-2026-66138 CVE OSSA-2026-027 — Ironic Python Agent root RCE (CVE-2026-66138). Reported by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) via the Metal3.io Security Team. The ntp_server… 2026-07-25
CVE-2026-54422 CVE OSSA-2026-028 — IPA credential extraction via malicious container (CVE-2026-54422). Reported by Yuliang Xiao. In the bootc deploy interface, a malicious container can extract the… 2026-07-25
OSSA-2026-025 OSSA OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… 2026-07-11
CVE-2026-54423 CVE OSSA-2026-025 — Ironic: RBAC bypass via IPMI send_raw (CVE-2026-54423). Discovered by Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson) of the Metal3.io Security Team. A… 2026-07-11
CVE-2026-44918 CVE OSSA-2026-026 — Ironic: Insufficient access controls on parent/child nodes (CVE-2026-44918). Same reporters. A project manager can reparent Volume Connectors/Targets across… 2026-07-11
OSSA-2026-024 OSSA OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… 2026-06-27
CVE-2026-50221 CVE OSSA-2026-024 / CVE-2026-50221 — Tim Shephard reported a server-side request forgery in Swift's proxy-server triggered via header injection: an authenticated user can coerce… 2026-06-27
OSSA-2026-023 OSSA [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… 2026-06-20
OSSA-2026-022 OSSA [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… 2026-06-20
OSSA-2026-017 OSSA [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… 2026-06-20
CVE-2026-55748 CVE [OSSN-0097 Errata 1] Horizon RC file escaping (CVE-2026-55748). The previously published Horizon RC-file generation issue now has a CVE assigned. (note) 2026-06-20
CVE-2026-54421 CVE [OSSA-2026-023] Ironic unredacted sensitive properties (CVE-2026-54421). POST/PATCH to /v1/volume/targets could return iSCSI credentials and other sensitive properties unredacted… 2026-06-20
CVE-2026-46448 CVE [OSSA-2026-022] Nova scheduler hint injection (CVE-2026-46448). Nova's server-create API does not strip internal scheduler hints, allowing authenticated users to bypass Placement… 2026-06-20
CVE-2026-46447 CVE [OSSA-2026-017 Errata 1] Ironic kernel command-line script injection (CVE-2026-46447). The original patches for this iPXE script-injection issue rejected some valid (especially… 2026-06-20
OSSA-2026-015 OSSA OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-06-13, 2026-05-30
OSSA-2026-016 OSSA OSSA-2026-016 (Neutron tagging policy bypass, CVE pending) — a singular/plural mismatch between the tagging controller's action names and policy rules lets project readers create… 2026-05-30
OSSA-2026-014 OSSA OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… 2026-05-30
CVE-2026-49017 CVE OSSA-2026-014 (Swift s3api DoS, CVE-2026-49017) — Alistair Coles (NVIDIA) reported that a truncated aws-chunked PUT puts a proxy-server worker into an infinite loop until it… 2026-05-30
CVE-2026-44394 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-43001 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-43000 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-42999 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
CVE-2026-42998 CVE OSSA-2026-015 (Keystone, five CVEs) is the most serious of the week. Boris Bobrov (SAP) found that an authenticated attacker can inject RBAC policy targets via the JSON request… 2026-05-30
OSSA-2026-013 OSSA The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
CVE-2026-44919 CVE The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
CVE-2024-47211 CVE The Ironic team shipped OSSA-2026-013 (CVE-2026-44919), a denial-of-service in Ironic's image-handling code. An authenticated user with node.instance_info write access can request… 2026-05-23
OSSA-2026-012 OSSA OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… 2026-05-16
CVE-2026-44916 CVE OSSA-2026-012 / CVE-2026-44916 — Remote code execution in the Ironic conductor when the Anaconda deploy interface is enabled. Users who can set node.instance_info['ks_template']… 2026-05-16
OSSA-2026-011 OSSA OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
OSSA-2026-010 OSSA OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… 2026-05-09
OSSA-2026-009 OSSA OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
CVE-2026-43002 CVE OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
CVE-2026-42997 CVE OSSA-2026-010 / CVE-2026-42997 — Ironic credential forwarding via iDRAC configuration molds. A user able to invoke molds clean/deploy steps can specify an arbitrary remote URL… 2026-05-09
CVE-2026-40214 CVE OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
CVE-2026-40213 CVE OSSA-2026-011 / CVE-2026-40213, CVE-2026-40214 — Cyborg multiple access-control vulnerabilities. Sean Mooney (Red Hat) reported two related issues. Default policy rules on device… 2026-05-09
CVE-2014-8124 CVE OSSA-2026-009 / CVE-2026-43002 — Horizon unauthenticated session flood. A regression of CVE-2014-8124 in Horizon 25.6.0+. The login view writes a next=URL post-login redirect into… 2026-05-09
OSSA-2026-006 OSSA OSSA-2026-006 — DOM-based XSS in Skyline Console (CVE pending). The instance console-log viewer rendered untrusted log content into a new browser window via document.write()… 2026-04-11
OSSA-2026-005 OSSA OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… 2026-04-11
CVE-2026-33551 CVE OSSA-2026-005 / CVE-2026-33551 — Restricted application credentials can create EC2 credentials. Maxence Bornecque (Orange Cyberdefense CERT) found that an authenticated user with… 2026-04-11
OSSA-2026-004 OSSA OSSA-2026-004 (Glance), CVE pending. Brian Rosmaita announced multiple Server-Side Request Forgery (SSRF) vulnerabilities in Glance image import, reported by Hyeongeun Ji (Open… 2026-03-21
OSSA-2026-003 OSSA OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… 2026-03-07
CVE-2026-28370 CVE OSSA-2026-003 / CVE-2026-28370 (Vitrage) — a remote code execution flaw in the Vitrage query parser, reported by Khalil Lemtaffah of Nokia. An authenticated user with Vitrage API… 2026-03-07
OSSA-2026-002 OSSA OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
CVE-2026-24709 CVE OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
CVE-2026-24708 CVE OSSA-2026-002 / CVE-2026-24708 — Nova, errata 1. Jeremy Stanley issued an errata correcting the CVE identifier on the previously announced Nova resize vulnerability. Dan Smith… 2026-02-21
OSSA-2026-001 OSSA Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… 2026-01-17
CVE-2026-22797 CVE Privilege escalation in keystonemiddleware (OSSA-2026-001 / CVE-2026-22797). Jeremy Stanley announced a vulnerability reported by Grzegorz Grasza (Red Hat) in the… 2026-01-17
OSSA-2025-002 OSSA OSSA-2025-002 — Unauthenticated Keystone access via EC2/S3 token endpoints (CVE pending). Reported by "kay" and announced by Jeremy Stanley on November 4: any deployment exposing… 2025-11-22, 2025-11-08
CVE-2025-65073 CVE OSSA-2025-002 (CVE-2025-65073) re-published with errata. Jeremy Stanley re-issued the Keystone EC2/S3 token endpoint advisory (also on openstack-announce). MITRE assigned… 2025-11-22
CVE-2025-58068 CVE Herve Beraud's eventlet update noted that CVE-2025-58068 (CVSS 6.3) in Eventlet's WSGI parser — enabling HTTP request smuggling — has been fixed in eventlet 0.40 (specific release… 2025-09-06

Advisory IDs link to the official source (security.openstack.org for OSSAs, cve.org for CVEs). Coverage dates link to the weekly issue that discussed each advisory.