CVE-2026-49017: [OSSA-2026-014] OpenStack Swift: Swift proxy-server denial of service via truncated s3api chunked upload (CVE-2026-49017)
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49017?
The severity of CVE-2026-49017 is classified as high with a CVSS score of 7.1.
How do I fix CVE-2026-49017?
To fix CVE-2026-49017, upgrade OpenStack Swift to version 2.36.2 or 2.37.2 or later.
What is the risk associated with CVE-2026-49017?
CVE-2026-49017 has a risk score of 40, indicating a significant potential impact.
What causes CVE-2026-49017?
CVE-2026-49017 is caused by the s3api middleware entering an infinite loop when processing a truncated aws-chunked PUT request body.
Which software is affected by CVE-2026-49017?
CVE-2026-49017 affects OpenStack Swift versions prior to 2.36.2 and 2.37.2.