CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-97404 CRITICAL

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticat…

CVSS 9.2 EPSS 0.27% Sep 24, 2026
CVE-2026-97149 MEDIUM

openstack-swift: openstack-swift: unauthorized read of other objects via TempURL and X-Copy-From

CVSS 5.3 EPSS 0.24% Sep 24, 2026
CVE-2026-94572 CRITICAL

openstack-octavia: octavia: HAProxy configuration injection via tls_ciphers on pools and listeners

CVSS 9.4 EPSS 0.53% Sep 21, 2026
CVE-2026-94571 CRITICAL

openstack-octavia: octavia: HAProxy configuration injection via L7 policy redirect_url and redirect_prefix

CVSS 9.4 EPSS 0.53% Sep 21, 2026
CVE-2026-93854 HIGH

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id}…

CVSS 7.2 EPSS 0.41% Sep 18, 2026
CVE-2026-93852 HIGH

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an adm…

CVSS 7.1 EPSS 0.37% Sep 18, 2026
CVE-2026-71198 HIGH

openstack-glance: openstack-glance: SSRF via location API missing host validation

CVSS 7.0 EPSS 0.45% Sep 14, 2026
CVE-2026-90461 MEDIUM

ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission

CVSS 6.3 EPSS 0.33% Sep 11, 2026
CVE-2026-90460 HIGH

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OA…

CVSS 7.6 EPSS 0.55% Sep 11, 2026
CVE-2026-80183 HIGH

keystone: OpenStack Keystone: Information disclosure via improper handling of domain IDs in role assignment listings

CVSS 7.1 EPSS 0.38% Aug 26, 2026
CVE-2026-80184 HIGH

keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication

CVSS 7.6 EPSS 0.60% Aug 25, 2026
CVE-2026-80182 HIGH

keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints

CVSS 7.6 EPSS 0.57% Aug 25, 2026
CVE-2026-77648 LOW

glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators

CVSS 2.2 EPSS 0.29% Aug 20, 2026
CVE-2026-76878 HIGH

aodh: python-watcher: aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization

CVSS 8.4 EPSS 0.54% Aug 19, 2026
CVE-2026-74250 MEDIUM

ironic: OpenStack Ironic: Autodetect deploy interface fails to run cleaning

CVSS 6.3 EPSS 0.30% Aug 14, 2026
CVE-2026-74248 MEDIUM

octavia: OpenStack Octavia: Authenticated user can prevent QoS policy deletion

CVSS 4.3 EPSS 0.33% Aug 14, 2026
CVE-2026-71194 MEDIUM

openstack-designate: designate: mDNS NOTIFY handler DoS via pool-blind zone lookup

CVSS 6.8 EPSS 0.52% Aug 12, 2026
CVE-2026-71193 CRITICAL

openstack-designate: designate: cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler

CVSS 9.6 EPSS 0.53% Aug 12, 2026
CVE-2026-71201 MEDIUM

ironic: OpenStack Ironic: Information disclosure via crafted request

CVSS 5.0 EPSS 0.28% Aug 5, 2026
CVE-2026-71192 MEDIUM

openstack-swift: openstack-swift: S3API cross-tenant object read via Swift-native header injection

CVSS 6.0 EPSS 0.44% Aug 5, 2026
CVE-2026-71191 MEDIUM

openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass

CVSS 6.0 EPSS 0.41% Aug 5, 2026
CVE-2026-71190 HIGH

openstack-swift: openstack-swift: Unauthenticated denial of service via catastrophic backtracking in Accept header parser

CVSS 8.7 EPSS 0.84% Aug 5, 2026
CVE-2026-55707 HIGH

openstack-neutron: openstack-neutron: Shared-network consumer can re-scope another project's subnets via subnetpool onboarding

CVSS 7.1 EPSS 0.43% Aug 5, 2026
CVE-2026-66139 MEDIUM

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

CVSS 4.8 EPSS 0.48% Jul 24, 2026
CVE-2026-66138 HIGH

ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration

CVSS 8.8 EPSS 0.78% Jul 24, 2026

Showing 1 to 25 CVEs · page 1 (more available)