UNKNOWN OpenStack

CVE-2026-66139

OSSA-2026-029: Zaqar EXTRA-SPEC header bypasses Keystone authentication

Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported that the Zaqar messaging service bypasses Keystone authentication when an EXTRA-SPEC header is present in the request. An unauthenticated attacker who knows a project UUID can read, enumerate, create, and delete that project’s queues without a Keystone token. The EXTRA-SPEC header was intended to support an alternative authentication mechanism, but the backend validation was never implemented, resulting

Affected Products

References

Published: 2026-07-23 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-07-23 via OpenStack. Affected: Zaqar: >=12.0.0 <20.1.1, ==21.0.0, ==22.0.0, CVE-2026-66139.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.