<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>vulnfeed — OpenStack</title>
    <link>https://vulnfeed.it</link>
    <description>OpenStack security vulnerabilities — vulnfeed.it</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 04 Aug 2026 17:55:03 +0000</lastBuildDate>
    <atom:link href="https://vulnfeed.it/feed/openstack.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>[UNKNOWN] CVE-2026-55707: [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding
 cross-project subnet mutation (CVE-2026-55707)</title>
    <link>https://www.openwall.com/lists/oss-security/2026/07/29/5</link>
    <description>[OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding
 cross-project subnet mutation (CVE-2026-55707)</description>
    <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://www.openwall.com/lists/oss-security/2026/07/29/5</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-66139: OSSA-2026-029: Zaqar EXTRA-SPEC header bypasses Keystone authentication</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-029.html</link>
    <description>Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported that the Zaqar messaging service bypasses Keystone authentication when an EXTRA-SPEC header is present in the request. An unauthenticated attacker who knows a project UUID can read, enumerate, create, and delete that project’s queues without a Keystone token. The EXTRA-SPEC header was intended to support an alternative authentication mechanism, but the backend validation was never implemented, resulting</description>
    <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-029.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] OSSN-0102: OSSN-0102: Neutron sub-resource APIs do not verify parent ownership</title>
    <link>https://wiki.openstack.org/wiki/OSSN/OSSN-0102</link>
    <description></description>
    <pubDate>Tue, 21 Jul 2026 14:00:57 +0000</pubDate>
    <guid isPermaLink="false">https://wiki.openstack.org/wiki/OSSN/OSSN-0102</guid>
  </item>
  <item>
    <title>[UNKNOWN] OSSN-0101: OSSN-0101: Nova console WebSocket proxy Origin allow-list poisoning</title>
    <link>https://wiki.openstack.org/wiki/OSSN/OSSN-0101</link>
    <description></description>
    <pubDate>Thu, 09 Jul 2026 18:33:19 +0000</pubDate>
    <guid isPermaLink="false">https://wiki.openstack.org/wiki/OSSN/OSSN-0101</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-54421: OSSA-2026-023: Sensitive properties returned unredacted in POST and PATCH HTTP responses</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-023.html</link>
    <description>Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) of the Metal3.io Security Team discovered a vulnerability in Ironic API RBAC handling, where a user with a valid token and credentials to send a POST or PATCH request to /v1/volume/targets can have potentially sensitive properties returned in the response unredacted, such as iSCSI credentials. Patches ¶ https://review.opendev.org/c/openstack/ironic/+/992335 (2023.1/antelope (unmaintained)) https://review.opendev.org/c/op</description>
    <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-023.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-46448: OSSA-2026-022: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-022.html</link>
    <description>Erichen from the Institute of Computing Technology, Chinese Academy of Sciences reported that Nova’s server create API does not strip internal scheduler hints. An authenticated user can bypass Placement resource claims and scheduling constraint enforcement, including availability zone, host aggregate, and image trait restrictions. The resulting instance has no Placement allocation, which can lead to compute node resource exhaustion and cross-tenant data persistence on NVMe devices after instance</description>
    <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-022.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-50266: OSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-021.html</link>
    <description>Tim Shephard from roiai.ca reported a policy enforcement bypass in Neutron’s default port RBAC rules. A project manager can create or update a port on a shared network owned by another project and set device_owner to a trusted network-service value such as network:dhcp . Depending on backend and deployment, this can bypass anti-spoofing and security group protections. This is a regression of CVE-2015-5240 (OSSA-2015-018) introduced by the manager role support change. Deployments running Neutron </description>
    <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-021.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] OSSN-0098: OSSN-0098: Mistral workflow execution context exposes Keystone auth token</title>
    <link>https://wiki.openstack.org/wiki/OSSN/OSSN-0098</link>
    <description></description>
    <pubDate>Wed, 03 Jun 2026 16:33:39 +0000</pubDate>
    <guid isPermaLink="false">https://wiki.openstack.org/wiki/OSSN/OSSN-0098</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-49299: OSSA-2026-016: Neutron tagging policy bypass allows project readers to mutate tags</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-016.html</link>
    <description>Tim Shephard from roiai.ca reported a policy enforcement bypass in Neutron’s tagging controller. The controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.</description>
    <pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-016.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-42998: OSSA-2026-015: Multiple credential delegation and authorization bypass vulnerabilities in Keystone</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-015.html</link>
    <description>Boris Bobrov from SAP SE reported that an authenticated attacker can inject RBAC policy targets via the JSON request body, bypassing authorization on any policy-protected endpoint to read credential secrets, create credentials for arbitrary users, and escalate to cloud admin (CVE-2026-42999). Application credential authentication does not verify the caller owns the credential, enabling user impersonation within a shared project (CVE-2026-42998). This impersonation can be chained with trusts to e</description>
    <pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-015.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-40213: OSSA-2026-011: Multiple access control vulnerabilities in Cyborg accelerator management</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-011.html</link>
    <description>Sean Mooney from Red Hat reported multiple access control vulnerabilities in OpenStack Cyborg. Default policy rules for device, deployable, and attribute API endpoints use an unconditional allow check that grants access to any authenticated user regardless of roles or project scope (CVE-2026-40213). Separately, Accelerator Request (ARQ) resources lack project ownership enforcement, allowing any authenticated user to enumerate, delete, or manipulate ARQs belonging to other projects (CVE-2026-4021</description>
    <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-011.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] CVE-2026-42997: OSSA-2026-010: Credential Forwarding to Arbitrary Endpoints via Ironic’s idrac Configuration molds Feature</title>
    <link>https://security.openstack.org/ossa/OSSA-2026-010.html</link>
    <description>Dmitry Tantsur and Tuomo Tanskanen from the Metal3.io Security Team reported a vulnerability in Ironic’s configuration mold import code for idrac. When importing a configuration mold, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. Operators choose the URL and the attacker has to a</description>
    <pubDate>Tue, 05 May 2026 00:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://security.openstack.org/ossa/OSSA-2026-010.html</guid>
  </item>
  </channel>
</rss>