OpenStack / Swift
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-97149 | openstack-swift: openstack-swift: unauthorized read of other objects via TempURL and X-Copy-From | MEDIUM | 5.3 | Sep 24, 2026 |
| CVE-2026-71192 | openstack-swift: openstack-swift: S3API cross-tenant object read via Swift-native header injection | MEDIUM | 6.0 | Aug 5, 2026 |
| CVE-2026-71191 | openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass | MEDIUM | 6.0 | Aug 5, 2026 |
| CVE-2026-71190 | openstack-swift: openstack-swift: Unauthenticated denial of service via catastrophic backtracking in Accept header parser | HIGH | 8.7 | Aug 5, 2026 |
| CVE-2026-50221 | openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server | MEDIUM | 5.3 | Jun 23, 2026 |
| CVE-2026-49017 | openstack-swift: OpenStack Swift: Denial of Service via truncated aws-chunked PUT request | HIGH | 7.1 | May 27, 2026 |
| CVE-2022-47950 | openstack-swift: Arbitrary file access through custom S3 XML entities | HIGH | 7.7 | Jan 18, 2023 |
| CVE-2017-8761 | openstack-swift: logs valid temporary urls which could result in access to data by anyone with access to the logfiles | MEDIUM | 4.3 | Jun 2, 2021 |
| CVE-2017-16613 | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy serv… | CRITICAL | 9.3 | Nov 21, 2017 |
| CVE-2016-0738 | openstack-swift: Proxy to server DoS through Large Objects | HIGH | 7.5 | Jan 29, 2016 |
| CVE-2016-0737 | openstack-swift: Client to proxy DoS through Large Objects | HIGH | 7.5 | Jan 29, 2016 |
| CVE-2015-5223 | openstack-swift: Information leak via Swift tempurls | MEDIUM | 5.0 | Oct 26, 2015 |
| CVE-2015-1856 | Swift: unauthorized deletion of versioned Swift object | MEDIUM | 5.5 | Apr 17, 2015 |
| CVE-2014-7960 | openstack-swift: Swift metadata constraints are not correctly enforced | MEDIUM | 4.0 | Oct 17, 2014 |
| CVE-2014-3497 | openstack-swift: XSS in Swift requests through WWW-Authenticate header | MEDIUM | 4.3 | Jul 3, 2014 |
| CVE-2013-6396 | python-swiftclient: SSL certificate verification security issue | CRITICAL | 9.3 | Feb 18, 2014 |
| CVE-2014-0006 | Swift: TempURL timing attack | HIGH | 8.7 | Jan 23, 2014 |
| CVE-2013-4155 | OpenStack: Swift Denial of Service using superfluous object tombstones | MEDIUM | 4.0 | Aug 20, 2013 |
| CVE-2012-4406 | Openstack-Swift: insecure use of python pickle() | CRITICAL | 9.8 | Oct 22, 2012 |
Showing 1 to 14 of 14 CVEs