https://seclists.org/oss-sec/2026/q2/408: [OSSA-2026-009] Horizon: Unauthenticated session flood via login dict storage (CVE-2026-43002)
Published May 5, 2026
·Updated
Affected Software
1 affected component
Openstack Horizon>=25.6.0<25.7.3
Frequently Asked Questions
1
What is the severity of CVE-2026-43002?
CVE-2026-43002 has been classified as a high-severity vulnerability.
2
What components are affected by CVE-2026-43002?
CVE-2026-43002 affects OpenStack Horizon versions 25.6.0 and above.
3
How can I fix CVE-2026-43002?
To fix CVE-2026-43002, users should upgrade OpenStack Horizon to the latest patched version.
4
What type of attack does CVE-2026-43002 enable?
CVE-2026-43002 enables an unauthenticated session flood attack via login dict storage.
5
When was CVE-2026-43002 published?
CVE-2026-43002 was published on May 5, 2026.