https://seclists.org/oss-sec/2026/q2/1005: [OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)
Published Jun 23, 2026
·Updated
Affected Software
1 affected component
Openstack Swift>=2.0.0<2.35.3, >=2.36.0<2.36.2, >=2.37.0<2.37.2
Frequently Asked Questions
1
What is the severity of CVE-2026-50221?
CVE-2026-50221 is classified as a medium severity vulnerability due to its potential for SSRF exploitation.
2
How do I mitigate CVE-2026-50221?
To mitigate CVE-2026-50221, upgrade OpenStack Swift to version 2.35.3 or any later version.
3
What types of systems are affected by CVE-2026-50221?
CVE-2026-50221 affects OpenStack Swift versions between 2.0.0 and 2.35.2, as well as certain ranges of later versions.
4
What is the impact of CVE-2026-50221?
The impact of CVE-2026-50221 includes the potential for unauthorized server-side requests, which could lead to information exposure or further exploits.
5
Who reported the CVE-2026-50221 vulnerability?
Tim Shephard from roiai.ca reported the CVE-2026-50221 vulnerability to the OpenStack security advisory team.