Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Swift MEDIUM 5.4
CVE-2026-50221

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Dele…

Fix: 2.35.3 / 2.36.2+
Fix from $1,600 2026-06-23
Nova HIGH 8.5
CVE-2026-46448

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Fix: 31.3.1 / 32.2.1+
Fix from $1,950 2026-06-16
Ironic HIGH 7.5
CVE-2026-50589

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…

Fix: 37.0.0+
Fix from $1,950 2026-06-05
Ironic HIGH 8.1
CVE-2026-48681

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Fix: 26.1.7 / 29.0.6+
Fix from $1,950 2026-06-04
Ironic HIGH 7.7
CVE-2026-46447

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Fix: 26.1.7 / 29.0.6+
Fix from $1,950 2026-06-03
Keystone HIGH 8.1
CVE-2026-44394

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-42998

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-42999

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Keystone HIGH 8.8
CVE-2026-43000

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-28
Ironic MEDIUM 6.5
CVE-2026-44919

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero …

Fix: 29.0.6 / 32.0.2+
Fix from $1,600 2026-05-14
Ironic HIGH 7.7
CVE-2026-42997

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a re…

Fix: 26.1.6 / 29.0.5+
Fix from $1,950 2026-05-05
Keystone HIGH 8.0
CVE-2026-43001

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-typ…

Fix: 27.0.2 / 28.0.2+
Fix from $1,950 2026-05-01
Ironic Python Agent HIGH 7.5
CVE-2026-43003

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within …

Fix: after 11.5.0
Fix from $1,950 2026-05-01
Ironic HIGH 7.2
CVE-2026-42510

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

Fix: 26.1.6 / 29.0.5+
Fix from $1,950 2026-04-28
Keystone MEDIUM 5.3
CVE-2026-33551

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create …

Fix: 26.1.1+
Fix from $1,600 2026-04-10
Glance MEDIUM 5.0
CVE-2026-34881

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authen…

Fix: 29.1.1 / 30.1.1+
Fix from $1,600 2026-03-31
Vitrage CRITICAL 9.1
CVE-2026-28370

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code executi…

Fix: 12.01 / 13.0.1+
Fix from $2,300 2026-02-27
Nova MEDIUM 6.5
CVE-2024-40767

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with …

Fix: 27.4.1 / 28.2.1+
Fix from $1,600 2024-07-24
Cinder MEDIUM 6.5
CVE-2024-32498

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom …

Fix: 22.1.3 / 23.1.1+
Fix from $1,600 2024-07-05
Magnum CRITICAL 9.8
CVE-2024-28718

An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

Patch available
Fix from $2,300 2024-04-12
Murano MEDIUM 6.5
CVE-2024-29156

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize th…

Fix: 3.0.0+
Fix from $1,600 2024-03-18
Glance Store MEDIUM 5.5
CVE-2024-1141

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level…

Fix: 4.7.0+
Fix from $1,600 2024-02-01
Horizon MEDIUM 6.1
CVE-2022-45582

Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

Fix: after 20.1.4
Fix from $1,600 2023-08-22
Kolla HIGH 8.8
CVE-2022-38060

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers wi…

Mitigation only
Fix from $1,950 2022-12-21
Tripleo Heat Templates MEDIUM 5.5
CVE-2021-3585

A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

Fix: 8.4.1+
Fix from $1,600 2022-08-26
Neutron MEDIUM 6.5
CVE-2021-40797

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API reques…

Fix: 16.4.1 / 17.2.1+
Fix from $1,600 2021-09-08
Neutron CRITICAL 9.1
CVE-2021-38598

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft i…

Fix: 16.4.1 / 17.1.3+
Fix from $2,300 2021-08-23
Keystone HIGH 7.5
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure duri…

Fix: 16.0.2 / 17.0.1+
Fix from $1,950 2021-08-06
Blazar Dashboard CRITICAL 9.9
CVE-2020-26943

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may tr…

Fix: 1.3.1+
Fix from $2,300 2020-10-16
Nova HIGH 8.3
CVE-2020-17376

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a so…

Fix: 19.3.1 / 20.3.1+
Fix from $1,950 2020-08-26