These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
OpenStack Glance vulnerability CVE-2026-71198 allows authenticated users to add locations pointing to internal endpoints and retrieve responses by downloading image data, potentially exposing sensitive information and internal endpoints like cloud metadata services. This high-severity issue requires immediate attention from OpenStack administrators and users with access to the Glance location API to verif [truncated]
OpenStack Ironic may send authentication credentials to an unexpected remote host when configured for HTTP(S) Basic Authentication with Image Service. This vulnerability affects OpenStack Ironic deployments using Image Service with HTTP(S) Basic Authentication. The issue may lead to potential credential leaks and unexpected remote host access. OpenStack administrators and security teams should assess expo [truncated]
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/cred [truncated]
CVE-2026-80183 is a vulnerability in OpenStack Keystone that allows any authenticated user holding the role:reader on any project to list every project-scoped role assignment under any domain. This issue arises from the misuse of 'None' in the list_role_assignments_for_tree function, enabling an attacker to harvest domain IDs and map role assignments across the entire cloud.
CVE-2026-76878 debrief based on the supplied source corpus. OpenStack Aodh before 22.0.1 has a vulnerability in its alarm list API. When the all_projects query parameter is set to false, the API bypasses project scoping. This allows non-admin users to list alarms from all projects, exposing sensitive metadata. The vulnerability also affects OpenStack Watcher, which lacks authorization for its webhook trig [truncated]
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization, allowing an authenticated user to prevent deletion of a QoS policy by associating it with an amphora. This affects all Octavia deployments. The vulnerability has a medium severity level and requires verification of OpenStack Octavia deployment versions and configurations to prevent potential QoS policy deletion bloc [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T23:17:22.170Z and has not been modified since then. OpenStack Designate before 22.0.2 is vulnerable to a REFUSED response to DNS queries via unauthenticated UDP packets when zones with the same name exist across different pools. This issue affects cross-tenant and cross-pool configurations, poten [truncated]
CVE-2026-71193 is a critical vulnerability in OpenStack Designate that allows an authenticated user to bypass zone creation checks and create overlapping zones. This could lead to cross-tenant DNS hijack, redirecting traffic to attacker-controlled IPs, and DNS denial of service, causing NODATA responses. The vulnerability exists in OpenStack Designate before version 22.0.1 and can be exploited by scheduli [truncated]
CVE-2026-71192 is a vulnerability in OpenStack Swift, a cloud storage system. The S3API middleware does not properly sanitize Swift-native control headers from S3 API requests when the s3_acl=true configuration is used. This allows an attacker to inject headers into a signed PUT request, potentially leading to unauthorized access to private objects in other tenants' accounts.
OpenStack Swift through 2.38.0 has a vulnerability in S3API middleware where it does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. This allows an attacker with a presigned PUT URL to inject an unsigned X-Amz-Copy-Source header, enabling them to perform a server-side copy from an arbitrary source object using the signer's authorization context. Cons [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T06:16:37.903Z and has not been modified since then. OpenStack Neutron before version 28.0.2 has a vulnerability in the subnetpool onboarding API, which does not verify ownership of target subnets, allowing authenticated users to onboard subnets from another project's shared network into their own [truncated]
A malicious bootc container deployed using ironic-python-agent may extract credentials used to download it. This issue affects OpenStack Ironic Python Agent through version 11.5.0. The vulnerability allows a malicious container to potentially access sensitive information. Defenders should assess their exposure and verify affected versions to mitigate potential risks. This issue requires careful review of [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T04:17:52.230Z and has not been modified since then. OpenStack Ironic before 37.0.1 has an IPMI command injection vulnerability. An Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypa [truncated]
A medium-severity vulnerability was found in OpenStack Ironic, tracked as CVE-2026-44918. This issue allows for the creation or modification of nodes across projects without proper authorization. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Administrators and users of OpenStack Ironic should be aware of this vulnerability and take necessary actions to mitigate it. The issue arises f [truncated]
CVE-2026-50221 is a server-side request forgery (SSRF) vulnerability in OpenStack Swift before version 2.37.2. The vulnerability allows an authenticated user with write access to inject internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. This can redirect container update requests to an attacker [truncated]
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. This issue may pose a security hardening opportunity to address certain types of user error. The vulnerability allows for potential security risks due to improper handling of project names in scripts generated for OpenStack RC file downloading. Affected deploym [truncated]
A vulnerability was discovered in OpenStack Nova before version 33.0.2. The server create API does not properly strip certain hint data, which can lead to an instance being created without a Placement allocation. This issue has a CVSS score of 5.4 and is classified as MEDIUM severity.
CVE-2026-50589 is a vulnerability in OpenStack Ironic 32 before 37.0.0. An unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. The CVSS score for this vulnerability is 5.3, and the severity is MEDIUM.
CVE-2026-50266 is a security vulnerability in OpenStack Neutron that allows a project manager to bypass security group protections and enable spoofing on shared networks. A project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has 'network:' at the beginning, such as 'network:dhcp'. The default port RBAC policies incorrectly included [truncated]
CVE-2026-44393 is a HIGH severity vulnerability in OpenStack oslo.messaging 1.0.0 through 17.3.0. The RabbitMQ driver fails to perform TLS hostname verification when connecting to the message broker. When `ssl_ca_file` is configured, the driver enables certificate chain validation but does not pass the expected broker hostname into the underlying TLS stack. This allows an attacker who can intercept contro [truncated]
A policy name mismatch in OpenStack Neutron's tagging controller allows project readers to create and update resource tags. The controller enforces plural policy action names (e.g., 'create_tags') while the policy rules use singular names (e.g., 'create_tag'). Under Neutron's default policy, mismatched names evaluate as allowed, granting unauthorized write access to tags on same-project resources. This af [truncated]
A vulnerability in OpenStack Keystone before 29.0.2 allows federated identity users to bypass token expiration policies through repeated token rescoping. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin fails to propagate the original token's expires_at value to the new token. The token provider then issues a replacemen [truncated]
A privilege escalation vulnerability in OpenStack Keystone before 29.0.2 allows an attacker with the member role on a project to escalate to admin privileges by chaining application credential impersonation with Keystone trusts. The vulnerability stems from improper authorization validation where Keystone validates delegated roles against the victim's actual role assignments in the database rather than th [truncated]
An RBAC policy enforcement bypass vulnerability exists in OpenStack Keystone before version 29.0.2. The flaw resides in the `enforce_call` method, where the RBAC policy enforcer unconditionally merges the raw JSON request body into the policy enforcement dictionary via `policy_dict.update(json_input.copy())`. This operation overwrites trusted target data previously populated from database lookups. Because [truncated]
OpenStack Swift before 2.36.2 and 2.37.2 has a denial-of-service vulnerability due to the s3api middleware entering an infinite loop when processing a truncated aws-chunked PUT request body. Authenticated attackers can cause proxy-server workers to become unresponsive, leading to service exhaustion. The defect was introduced in Swift 2.36.0 and can be exploited by authenticated attackers. Defenders should [truncated]
CVE-2026-44919 describes an availability issue in OpenStack Ironic image handling. In affected versions through 35.x before commit a3f6d73, a file:///dev/zero URL can cause checksum calculations to loop indefinitely, potentially consuming worker resources and delaying image-related operations.
CVE-2026-44916 is a low-severity issue in OpenStack Ironic affecting versions before 35.0.2 in a certain non-default configuration. The published description says instance_info['ks_template'] is rendered without sandboxing. Public records show the CVE was first published on 2026-05-08 and later modified on 2026-05-20, with references to a Launchpad bug, an OpenStack security advisory, and an oss-security [truncated]
A critical vulnerability was discovered in OpenStack Ironic, a popular open-source cloud infrastructure service. The issue allows users to request authorization to be sent to a remote endpoint during import operations, potentially exposing sensitive credentials. The vulnerability has a CVSS score of 7.7 and is considered HIGH severity. The affected versions of Ironic are 17.0.0 to 26.1.6, 27.0.0 to 29.0.5 [truncated]
A vulnerability was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. The issue allows unauthenticated requests to write to the session storage backend, potentially leading to storage exhaustion. This is a regression of the fix for CVE-2014-8124. The vulnerability exists due to a write operation to the session storage backend before authentication, allowing unauthenticated requests to potential [truncated]
CVE-2026-42510 affects OpenStack Ironic before 35.0.1. In a non-default configuration that includes the console interface, the issue can allow ipmitool execution. The supplied CVSS data rates it Medium (6.6), but the impact remains significant because the vector indicates network reachability, no user interaction, and high confidentiality, integrity, and availability impact with high privileges required.