https://seclists.org/oss-sec/2026/q2/780: [OSSA-2026-014] OpenStack Swift: Errata 1 - Proxy-server denial of service via truncated s3api chunked upload, (CVE-2026-49017)
Published Jun 2, 2026
·Updated
Affected Software
1 affected component
Openstack Swift>=2.35.1<2.35.3, >=2.36.0<2.36.2, >=2.37.0<2.37.2
Frequently Asked Questions
1
What is the severity of CVE-2026-49017?
CVE-2026-49017 has been rated as a high severity vulnerability due to its potential to cause a denial of service.
2
What does CVE-2026-49017 affect?
CVE-2026-49017 affects OpenStack Swift versions >=2.35.1 <2.35.3, >=2.36.0 <2.36.2, and >=2.37.0 <2.37.2.
3
How do I fix CVE-2026-49017?
To fix CVE-2026-49017, upgrade OpenStack Swift to versions 2.35.3, 2.36.2, or 2.37.2 or later.
4
What type of vulnerability is CVE-2026-49017?
CVE-2026-49017 is a vulnerability that allows for a denial of service through truncated S3 API chunked uploads.
5
When was CVE-2026-49017 published?
CVE-2026-49017 was published on June 2, 2026.