https://seclists.org/oss-sec/2026/q3/227: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending)
Published Jul 23, 2026
·Updated
Affected Software
1 affected component
Openstack Zaqar>=12.0.0<20.1.1, =21.0.0, =22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-pending?
The severity of CVE-2026-pending is currently under assessment, but it is related to a potential bypass of Keystone authentication.
2
How do I fix CVE-2026-pending?
To fix CVE-2026-pending, update OpenStack Zaqar to a version that addresses this vulnerability, specifically versions later than 20.1.
3
What components are affected by CVE-2026-pending?
CVE-2026-pending affects OpenStack Zaqar versions 12.0.0 to below 20.1.
4
What is the nature of the exploit in CVE-2026-pending?
CVE-2026-pending involves an exploit that allows the EXTRA-SPEC header to bypass Keystone authentication.
5
When was CVE-2026-pending published?
CVE-2026-pending was published on July 23, 2026.