https://seclists.org/oss-sec/2026/q2/133: [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE PENDING)
Published Apr 14, 2026
·Updated
Affected Software
1 affected component
Openstack Keystone>=8.0.0<25.0.1, >=26.0.0<26.1.1, >=27.0.0<27.0.1, >=28.0.0<28.0.1
Frequently Asked Questions
1
What is the severity of OSSA-2026-007?
The severity of OSSA-2026-007 is currently classified as pending until further analysis is complete.
2
How do I fix OSSA-2026-007?
To fix OSSA-2026-007, ensure that your OpenStack Keystone configuration correctly interprets the enabled attribute as a boolean.
3
What systems are affected by OSSA-2026-007?
The OSSA-2026-007 vulnerability affects the LDAP identity backend in OpenStack Keystone.
4
When was OSSA-2026-007 announced?
OSSA-2026-007 was announced on April 14, 2026.
5
Is there a workaround for OSSA-2026-007?
Currently, there is no officially documented workaround for OSSA-2026-007, and users are advised to monitor for updates.