https://seclists.org/oss-sec/2026/q3/314: [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)
Published Jul 28, 2026
·Updated
Affected Software
1 affected component
Openstack Swift>=2.18.0<2.35.4, >=2.36.0<2.36.3, >=2.37.0<2.37.3, =2.38.0
Frequently Asked Questions
1
What is the severity of CVE-2026-pending?
CVE-2026-pending is classified as a high severity vulnerability due to its potential to bypass authorization and expose sensitive data.
2
How do I fix CVE-2026-pending?
To fix CVE-2026-pending, it is recommended to upgrade OpenStack Swift to versions 2.35.4, 2.36.3, or higher.
3
Who is affected by CVE-2026-pending?
CVE-2026-pending affects OpenStack Swift versions between 2.18.0 and 2.35.4, versions between 2.36.0 and 2.36.3, and versions between 2.37.0 and below.
4
What are the implications of CVE-2026-pending?
CVE-2026-pending allows unauthorized users to bypass S3API header authorization, potentially leading to unauthorized access to resources.
5
Is there a workaround for CVE-2026-pending?
While upgrading is the best solution, temporarily restricting access to affected Swift services can serve as a workaround until the upgrade can be performed.