UNKNOWN OpenStack
CVE-2026-66139
OSSA-2026-029: Zaqar EXTRA-SPEC header bypasses Keystone authentication
Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported that the Zaqar messaging service bypasses Keystone authentication when an EXTRA-SPEC header is present in the request. An unauthenticated attacker who knows a project UUID can read, enumerate, create, and delete that project’s queues without a Keystone token. The EXTRA-SPEC header was intended to support an alternative authentication mechanism, but the backend validation was never implemented, resulting
Affected Products
- Zaqar: >=12.0.0 <20.1.1, ==21.0.0, ==22.0.0
- CVE-2026-66139
References
- https://security.openstack.org/ossa/OSSA-2026-029.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-66139
This unknown severity vulnerability was published on 2026-07-23 via OpenStack. Affected: Zaqar: >=12.0.0 <20.1.1, ==21.0.0, ==22.0.0, CVE-2026-66139.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.