https://seclists.org/oss-sec/2026/q2/714: [OSSA-2026-014] OpenStack Swift: Swift proxy-server denial of service via truncated s3api chunked upload (CVE-2026-49017)
Published May 27, 2026
·Updated
Affected Software
1 affected component
Openstack Swift>=2.36.0<2.36.2, >=2.37.0<2.37.2
Frequently Asked Questions
1
What is the severity of CVE-2026-49017?
CVE-2026-49017 is classified as a denial of service vulnerability.
2
How do I fix CVE-2026-49017?
To fix CVE-2026-49017, upgrade OpenStack Swift to version 2.36.2 or 2.37.2 or later.
3
Which OpenStack Swift versions are affected by CVE-2026-49017?
CVE-2026-49017 affects OpenStack Swift versions >=2.36.0 <2.36.2 and >=2.37.0 <2.37.2.
4
What causes the denial of service in CVE-2026-49017?
The denial of service in CVE-2026-49017 is caused by a vulnerability in the Swift proxy-server during truncated S3 API chunked uploads.
5
Is CVE-2026-49017 exploit-related to S3 API functionality?
Yes, CVE-2026-49017 specifically impacts S3 API functionality within the OpenStack Swift proxy-server.