SecAlerts
O

OpenStack

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 456 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 26, 2011 to present

456
Total CVEs
124
Critical+High
0
Exploited
51
Unpatched

Threat Assessment

Avg CVSS
5.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
51
Critical/High
Risk Level
45/100
medium
🆕 5Fresh (<7d)📈 18 in Last 30 Days

Severity Distribution

Critical
20
High
104
Medium
207
Low
52

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
46
2
XSS
20
3
Input Validation
14
4
Path Traversal
8
5
Buffer Overflow
7

Most Affected Products

1. Openstack Keystone161
2. Openstack Swift141
3. Openstack Nova123
4. Openstack Neutron107
5. redhat Openstack92

Recent Vulnerabilities

See more →
CVE-2026-71196
unknown

[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)

Sep 3, 2026🔧 No Patch
CVE-2026-71197
unknown

[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)

Sep 3, 2026🔧 No Patch
CVE-2026-71198
unknown

[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)

Sep 3, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/642
unknown

[OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)

Sep 3, 2026🔧 No Patch
CVE-2026-80183
CVSS 7.1high
Aug 26, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/577
unknown

[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184)

Aug 25, 2026🔧 No Patch
CVE-2026-80184
CVSS 7.6high

[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184)

Aug 25, 2026🔧 No Patch
CVE-2026-80182
CVSS 7.6high

[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184)

Aug 25, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q3/573
unknown

[OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-pending)

Aug 25, 2026🔧 No Patch
CVE-2026-77648
CVSS 2.2low
Aug 20, 2026🔧 No Patch

Monitor OpenStack in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.