https://seclists.org/oss-sec/2026/q3/315: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)
Published Jul 28, 2026
·Updated
Affected Software
1 affected component
Openstack Swift>=1.9.1<2.35.4, >=2.36.0<2.36.3, >=2.37.0<2.37.3, =2.38.0
Frequently Asked Questions
1
What is the severity of CVE-2026-pending?
CVE-2026-pending has been identified as a denial-of-service vulnerability in OpenStack Swift.
2
How do I fix CVE-2026-pending?
To resolve CVE-2026-pending, you should upgrade OpenStack Swift to version 2.36.3 or later.
3
Which versions of OpenStack Swift are affected by CVE-2026-pending?
CVE-2026-pending affects OpenStack Swift versions 1.9.1 to 2.35.4 and versions 2.36.0 to 2.36.2.
4
What kind of attack is possible with CVE-2026-pending?
CVE-2026-pending allows an attacker to execute a denial-of-service (DoS) attack via a malicious Accept header.
5
When was CVE-2026-pending published?
CVE-2026-pending was published on July 28, 2026.