Back

MEDIUM

openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass

Published Aug 5, 2026

Description

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) ship openstack-swift and are affected by this vulnerability. In default RHOSO deployments, the s3api filter is included in the active proxy-server pipeline, and the s3_acl option is not explicitly set (defaulting to false). SigV4 presigned URL requests are processed through the S3API middleware and are vulnerable. All RHOSP (13, 16.2, 17.1) and RHOSO (18.0) deployments with s3api enabled in the pipeline are affected.

Red Hat mitigation

If S3 API compatibility is not required, remove the s3api filter from the proxy-server pipeline in proxy-server.conf. This completely eliminates the attack surface. If S3 API is required, restrict the distribution and scope of presigned PUT URLs as an operational control, and apply the upstream patch when available. There is no configuration-only workaround that fully mitigates this issue while keeping S3 API functionality enabled.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 5, 2026
Updated Aug 6, 2026
Reserved Aug 5, 2026
CISA Vulnrichment
Updated Aug 6, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity Important
Public date Jul 28, 2026