openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass
Published Aug 5, 2026
6.0
MEDIUMCVSS 4.0
EPSS 0.41%
Description
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
Affected products
-
- Version 2.18.0StatusaffectedConstraints<2.35.4
- Version 2.36.0StatusaffectedConstraints<2.36.3
- Version 2.37.0StatusaffectedConstraints<2.37.3
- Version 2.38.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-account
Will not fix
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-base
Will not fix
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-container
Will not fix
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-object
Will not fix
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-proxy-server
Will not fix
Red Hat OpenStack Platform 16.2
openstack-swift
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-account
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-base
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-container
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-object
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-proxy-server
Affected
Red Hat OpenStack Platform 17.1
openstack-swift
Affected
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-account
Affected
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-base
Affected
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-container
Affected
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-object
Affected
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-proxy-server
Affected
Red Hat OpenStack Platform 18.0
openstack-swift
Affected
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-account-rhel9
Affected
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-base-rhel9
Affected
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-container-rhel9
Affected
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-object-rhel9
Affected
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-proxy-server-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-account | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-base | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-container | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-object | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-proxy-server | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | openstack-swift | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-account | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-base | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-container | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-object | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-proxy-server | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | openstack-swift | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-account | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-base | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-container | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-object | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-proxy-server | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | openstack-swift | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-account-rhel9 | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-base-rhel9 | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-container-rhel9 | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-object-rhel9 | Affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-proxy-server-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) ship openstack-swift and are affected by this vulnerability. In default RHOSO deployments, the s3api filter is included in the active proxy-server pipeline, and the s3_acl option is not explicitly set (defaulting to false). SigV4 presigned URL requests are processed through the S3API middleware and are vulnerable. All RHOSP (13, 16.2, 17.1) and RHOSO (18.0) deployments with s3api enabled in the pipeline are affected.
Red Hat mitigation
If S3 API compatibility is not required, remove the s3api filter from the proxy-server pipeline in proxy-server.conf. This completely eliminates the attack surface. If S3 API is required, restrict the distribution and scope of presigned PUT URLs as an operational control, and apply the upstream patch when available. There is no configuration-only workaround that fully mitigates this issue while keeping S3 API functionality enabled.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-71191 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2503670 Issue Tracking
- https://launchpad.net/bugs/2158733 issue-tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-71191
- https://openwall.com/lists/oss-security/2026/07/28/26 mailing-listvendor-advisory
- https://security.openstack.org/ossa/OSSA-2026-030.html vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-71191
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-71191 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2503670 | Issue Tracking | |
| https://launchpad.net/bugs/2158733 | issue-tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-71191 | ||
| https://openwall.com/lists/oss-security/2026/07/28/26 | mailing-listvendor-advisory | |
| https://security.openstack.org/ossa/OSSA-2026-030.html | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-71191 |
Change history (0)
No recorded changes yet.