Where
-Infinity
0

Openstack IronicIn OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediat…

Risk 37
Severity
6.3
First published (updated )

Openstack OctaviaOpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associ…

Risk 22
Severity
4.3
First published (updated )

Openstack DesignateIn OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving re…

Risk 40
Severity
6.8
First published (updated )

Openstack DesignateIn OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the dupl…

Risk 68
Severity
9.6
First published (updated )

oss-sec[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192)

oss-sec[OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE-2026-40683)

oss-sec[OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)

Openstack Ironic[OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)

Risk 27
Severity
5
First published (updated )

Openstack OpenStack Swift[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192)

Risk 37
Severity
6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Openstack Swift[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192)

Risk 37
Severity
6
First published (updated )

Openstack Swift[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190)

Risk 50
Severity
8.7
First published (updated )

Openstack NeutronIn OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the t…

Risk 49
Severity
7.1
First published (updated )

oss-sec[OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)

oss-sec[OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)

Openstack Zaqar[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)

Risk 34
Severity
4.8
First published (updated )

Openstack Ironic Python Agent[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)

Risk 70
Severity
7.2
First published (updated )

oss-sec[OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-pending)

Openstack Ironic Python Agent[OSSA-2026-028] OpenStack Ironic Python Agent: Cdential extraction via malicious container (CVE-2026-54422)

Risk 33
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-pending)

Openstack GlanceGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

Risk 43
Severity
8.2
First published (updated )

oss-sec[OSSA-2026-026] Ironic: Insufficient Access Controls garding pant/child nodes

First published (updated )

Openstack Ironic[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)

Risk 61
Severity
8.2
First published (updated )

oss-sec[OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Openstack IronicOpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project withou…

Risk 41
Severity
5.5
First published (updated )

Openstack Swift[OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)

Risk 36
Severity
5.3
First published (updated )

oss-sec[OSSA-2026-024] OpenStack Swift: Swift proxy-server SSRF via header injection (CVE-2026-50221)

Openstack OpenStack HorizonOS Command Injection

Risk 49
Severity
6
First published (updated )

oss-sec[OSSA-2026-023] Ironic: Sensitive properties turned undacted in POST and PATCH HTTP sponses (CVE-2026-54421)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203