PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43002 OpenStack CVE debrief

A vulnerability was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. The issue allows unauthenticated requests to write to the session storage backend, potentially leading to storage exhaustion. This is a regression of the fix for CVE-2014-8124. The vulnerability exists due to a write operation to the session storage backend before authentication, allowing unauthenticated requests to potentially exhaust storage.

Vendor
OpenStack
Product
Horizon
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-07-24
Advisory published
2026-05-05
Advisory updated
2026-07-24

Who should care

Users of OpenStack Horizon 25.6 and 25.7 before 25.7.3 should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and applying vendor remediations, implementing compensating controls, and performing inventory checks to identify and update vulnerable systems.

Technical summary

The vulnerability exists in OpenStack Horizon 25.6 and 25.7 before 25.7.3 due to a write operation to the session storage backend before authentication. This allows unauthenticated requests to potentially exhaust storage, as the session storage can be filled with data from these requests. The issue is a regression of the fix for CVE-2014-8124. Users of OpenStack Horizon 25.6 and 25.7 before 25.7.3 should be aware of this vulnerability and take steps to mitigate it by reviewing and applying vendor remediations, implementing compensating controls, and performing inventory checks to identify and update vulnerable systems. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. It is crucial for users to verify the information with official sources for the most up-to-date details and to plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Defensive priority

Medium priority due to the potential for storage exhaustion and the relatively low CVSS score of 5.3.

Recommended defensive actions

  • Review and apply the vendor's remediation for OpenStack Horizon 25.6 and 25.7 before 25.7.3.
  • Implement compensating controls to monitor and limit unauthenticated requests to the session storage backend.
  • Perform inventory checks to identify and update vulnerable systems.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record was published on 2026-05-05T17:17:04.920Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Awaiting Analysis. This information is based on the provided source corpus and may not reflect the current status. Users should verify the information with the official sources for the most up-to-date details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T17:17:04.920Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.