14 entries matching openstack — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-71198 | In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to | HIGH | 7.0 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-90460 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 c | HIGH | 7.6 | 27%ile | NVD | 2026-09-11 |
| CVE-2026-90461 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is conf | MEDIUM | 6.3 | 11%ile | NVD | 2026-09-11 |
| CVE-2026-71196 | OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs | HIGH | 7.0 | — | OpenStack | 2026-09-03 |
| CVE-2022-44020 | OSSN-0091: BMC emulators developed in OpenStack community do not preserve passwords on VMs | UNKNOWN | — | 14%ile | OpenStack | 2026-08-27 |
| CVE-2024-29156 | OSSN-0093: = Unsafe Environment Handling in MuranoPL = | UNKNOWN | — | 53%ile | OpenStack | 2026-08-27 |
| CVE-2020-27781 | OSSN-0087: = Ceph user credential leakage to consumers of OpenStack Manila = | UNKNOWN | — | 24%ile | OpenStack | 2026-08-27 |
| CVE-2015-0204 | OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)= | UNKNOWN | — | 100%ile | OpenStack | 2026-08-27 |
| OSSN-0073 | OSSN-0073: = Horizon dashboard leaks internal information through cookies = | UNKNOWN | — | — | OpenStack | 2026-08-27 |
| OSSN-0053 | OSSN-0053: = Keystone token disclosure may result in malicious trust creation = | UNKNOWN | — | — | OpenStack | 2026-08-27 |
| OSSN-0055 | OSSN-0055: = Service accounts may have cloud admin privileges = | UNKNOWN | — | — | OpenStack | 2026-08-27 |
| CVE-2026-80182 | OSSA-2026-037: Inconsistent scope enforcement for delegated tokens in Keystone | UNKNOWN | — | 42%ile | OpenStack | 2026-08-25 |
| CVE-2026-76878 | OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass | UNKNOWN | — | 40%ile | OpenStack | 2026-08-19 |
| CVE-2026-71193 | OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling | UNKNOWN | — | 31%ile | OpenStack | 2026-08-11 |