← Back to feed Search feed

OpenStack vulnerabilities

14 entries matching openstack — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to HIGH7.038%ileNVD2026-09-14
CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 cHIGH7.627%ileNVD2026-09-11
CVE-2026-90461OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is confMEDIUM6.311%ileNVD2026-09-11
CVE-2026-71196OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIsHIGH7.0OpenStack2026-09-03
CVE-2022-44020OSSN-0091: BMC emulators developed in OpenStack community do not preserve passwords on VMsUNKNOWN14%ileOpenStack2026-08-27
CVE-2024-29156OSSN-0093: = Unsafe Environment Handling in MuranoPL =UNKNOWN53%ileOpenStack2026-08-27
CVE-2020-27781OSSN-0087: = Ceph user credential leakage to consumers of OpenStack Manila =UNKNOWN24%ileOpenStack2026-08-27
CVE-2015-0204OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)=UNKNOWN100%ileOpenStack2026-08-27
OSSN-0073OSSN-0073: = Horizon dashboard leaks internal information through cookies =UNKNOWNOpenStack2026-08-27
OSSN-0053OSSN-0053: = Keystone token disclosure may result in malicious trust creation =UNKNOWNOpenStack2026-08-27
OSSN-0055OSSN-0055: = Service accounts may have cloud admin privileges =UNKNOWNOpenStack2026-08-27
CVE-2026-80182OSSA-2026-037: Inconsistent scope enforcement for delegated tokens in KeystoneUNKNOWN42%ileOpenStack2026-08-25
CVE-2026-76878OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook authorization bypassUNKNOWN40%ileOpenStack2026-08-19
CVE-2026-71193OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool schedulingUNKNOWN31%ileOpenStack2026-08-11