PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61422 Apache Software Foundation CVE debrief

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicious template or ISO registration risk, as URL validation still occurs prior to the actual download by the Secondary Storage VM. This issue affects Apache CloudStack: in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Vendor
Apache Software Foundation
Product
Apache CloudStack
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Apache CloudStack users and administrators should be aware of this vulnerability and take immediate action to upgrade to a fixed version. This vulnerability affects the security and integrity of the CloudStack environment, and users should verify URL validation and secondary storage usage-limit checks to prevent potential attacks. Security teams and vulnerability management teams should prioritize this issue and ensure that affected systems are upgraded or mitigated accordingly. Additionally, operators and platform administrators should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Compensating controls, monitoring, and asset inventory reviews are also recommended while remediation is scheduled and verified. Rollback and change window planning should be considered for exposed systems. Source tracking and exposure reviews are also essential to ensure the vulnerability is properly managed. It is crucial for users to understand the potential risks and take proactive measures to protect their environments. The CVE record and NVD details provide further information on the vulnerability and its potential impact. Users should also consider the vendor's guidance and support resources to address this issue effectively. Overall, a comprehensive review of the vulnerability and its implications is necessary to ensure the security and integrity of Apache CloudStack deployments. This includes verifying the effectiveness of current security controls and implementing additional measures as needed to prevent potential attacks. By taking a proactive and informed approach, users can minimize the risks associated with this vulnerability and maintain the security and reliability of their CloudStack environments. Therefore, it is essential for users to prioritize this issue and take immediate action to address it. The recommended actions and resource links provided can help guide users through the remediation process and ensure that their environments are properly secured. In summary, Apache CloudStack users and administrators must take immediate action to upgrade to a fixed version, review and implement compensating controls,

Technical summary

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. The vulnerability occurs when CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks before URL validation is performed. This issue affects Apache CloudStack in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. The vulnerability has a significant impact on the security posture of Apache CloudStack users, as it could allow attackers to perform SSRF attacks.

Defensive priority

Upgrade to fixed version

Recommended defensive actions

  • Upgrade to version 4.20.3.1 or 4.22.1.1 or later
  • Verify URL validation and secondary storage usage-limit checks
  • Monitor for suspicious template and ISO registration activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from official CVE and NVD sources indicates an authenticated pre-validation SSRF vulnerability exists in Apache CloudStack's template and ISO registration functionality. However, details are limited, and further verification is recommended. The vulnerability occurs when CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks before URL validation is performed. This issue affects Apache CloudStack in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. Evidence limits suggest verifying URL validation and secondary storage usage-limit checks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:39.840Z and has not been modified since then.