Where
-Infinity
0
Severity
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

First published (updated )
Severity
9
AV:N/AC:L/Au:S/C:C/I:C/A:C

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

First published (updated )
Severity
7.6
AV:N/AC:H/Au:N/C:C/I:C/A:C

Kashyap Chamarthy <kchamart> reports:

It's possible for Neutron (OpenStack networking) users to pass arbitrary config files via rootwrap[] which allows privilege escalation by letting user add more exec directories, change configurations of commands using rootwrap, log more than what needs to be done, etc.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extradhcpopts value.

First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

1 / 3
Source: Launchpad
First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in openstack-neutron. When merging port ranges, the code never assumed the conjunction ID might not be present in the set due to already being removed. This can lead to server crash and denial of service.

Upstream patch:

https://review.openstack.org/#/c/640252/ https://review.openstack.org/#/c/648102/2 https://review.openstack.org/#/c/648004/2 https://review.openstack.org/#/c/648003/2 https://review.openstack.org/#/c/648002/2

References:

https://bugs.launchpad.net/ubuntu/+source/neutron/+bug/1813007 https://bugs.launchpad.net/ossa/+bug/1813007 https://review.openstack.org/#/q/topic:bug/1813007

1 / 2
Source: Red Hat
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or denial of service.

First published (updated )
Severity
5.9
Race Condition
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

1 / 2
First published (updated )
Severity
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

First published (updated )
Severity
4

Steven Hardy reports: Currently we don't set the NeutronMetadataProxySharedSecret, (which according to the description in the neutron docs exists to prevent spoofing) - thus is remains at it's bad default value of "unset".

I assume this has the potential for security impact given that if it's predictable I guess spoofing metadata requests then becomes possible, but not being a Neutron expert I'm not sure of how serious an issue this may be.

First published (updated )
Severity
3.5
AV:N/AC:M/Au:S/C:N/I:N/A:P

The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.

First published (updated )
Severity
3.5
Race Condition
AV:N/AC:M/Au:S/C:N/I:P/A:N

It was reported that a vulnerability was found in Neutron. By changing the device owner of an instance's port right after it is created, an authenticated user may prevent application of firewall rules and so avoid IP anti-spoofing controls. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected.

Vulnerability affects versions through 2014.2.3 and 2015.1 versions through 2015.1.1

Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Kevin Benton from Mirantis as the original reporter.

1 / 2
Source: Red Hat
First published (updated )
Severity
2.2
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set deviceowner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECTMANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018).

First published (updated )
Severity
2.1
AV:N/AC:H/Au:S/C:P/I:N/A:N

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

First published (updated )

================================================================================== ==================================================================================

:Date: May 28, 2026 :CVE: CVE-2026-pending

Affects ~~~~~~~ - Neutron: >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, >=28.0.0 <28.0.1

Description ~~~~~~~~~~~ Patches ~~~~~~~ - https://review.opendev.org/989376 (2025.1/epoxy) - https://review.opendev.org/989375 (2025.2/flamingo) - https://review.opendev.org/989374 (2026.1/gazpacho) - https://review.opendev.org/989099 (2026.2/hibiscus)

Credits ~~~~~~~ - Tim Shephard from roiai.ca (CVE-2026-pending)

References ~~~~~~~~~~ - https://launchpad.net/bugs/2150132 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes ~~~~~ - CVE assignment is pending (MITRE CAN-2026-2030611).

-- Goutham Pacha Ravi (gouthamr) OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

================================================================================== ==================================================================================

:Date: May 28, 2026 :CVE: CVE-2026-49299

Affects ~~~~~~~ - Neutron: >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, >=28.0.0 <28.0.1

Description ~~~~~~~~~~~ Errata ~~~~~~ Patches ~~~~~~~ - https://review.opendev.org/989376 (2025.1/epoxy) - https://review.opendev.org/989375 (2025.2/flamingo) - https://review.opendev.org/989374 (2026.1/gazpacho) - https://review.opendev.org/989099 (2026.2/hibiscus)

Credits ~~~~~~~ - Tim Shephard from roiai.ca (CVE-2026-49299)

References ~~~~~~~~~~ - https://launchpad.net/bugs/2150132 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49299

OSSA History ~~~~~~~~~~~~ - 2026-05-28 - Errata 1 - 2026-05-28 - Original Version

-- Goutham Pacha Ravi (gouthamr) OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

====================================================================================================================== ======================================================================================================================

:Date: June 04, 2026 :CVE: CVE-2026-pending

Affects ~~~~~~~ - Neutron: >=25.0.0 <25.2.4, >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0

Description ~~~~~~~~~~~ Patches ~~~~~~~ - https://review.opendev.org/991523 (2025.1/epoxy) - https://review.opendev.org/990356 (2025.2/flamingo) - https://review.opendev.org/990353 (2026.1/gazpacho) - https://review.opendev.org/990273 (2026.2/hibiscus)

Credits ~~~~~~~ - Tim Shephard from roiai.ca (CVE-2026-pending)

References ~~~~~~~~~~ - https://launchpad.net/bugs/2152115 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes ~~~~~ - A CVE request has been filed with MITRE (CAN-2026-2030702). - This is a regression of CVE-2015-5240 (OSSA-2015-018).

-- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

Errata 1 for OSSA-2026-021: CVE-2026-50266 has been assigned.

====================================================================================================================== ======================================================================================================================

:Date: June 04, 2026 :CVE: CVE-2026-50266

Affects ~~~~~~~ - Neutron: >=25.0.0 <25.2.4, >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0

Description ~~~~~~~~~~~ Errata ~~~~~~ CVE-2026-50266 has been assigned for this vulnerability.

Patches ~~~~~~~ - https://review.opendev.org/991523 (2025.1/epoxy) - https://review.opendev.org/990356 (2025.2/flamingo) - https://review.opendev.org/990353 (2026.1/gazpacho) - https://review.opendev.org/990273 (2026.2/hibiscus)

Credits ~~~~~~~ - Tim Shephard from roiai.ca (CVE-2026-50266)

References ~~~~~~~~~~ - https://launchpad.net/bugs/2152115 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50266

Notes ~~~~~ - This is a regression of CVE-2015-5240 (OSSA-2015-018).

OSSA History ~~~~~~~~~~~~ - 2026-06-04 - Errata 1 - 2026-06-04 - Original Version

-- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

On 6/4/26 8:00 AM, Goutham Pacha Ravi wrote: ====================================================================================================================== ======================================================================================================================

:Date: June 04, 2026 :CVE: CVE-2026-pending

Affects ~~~~~~~ - Neutron: >=25.0.0 <25.2.4, >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0

Description ~~~~~~~~~~~ Patches ~~~~~~~ - https://review.opendev.org/991523 (2025.1/epoxy) - https://review.opendev.org/990356 (2025.2/flamingo) - https://review.opendev.org/990353 (2026.1/gazpacho) - https://review.opendev.org/990273 (2026.2/hibiscus)

Credits ~~~~~~~ - Tim Shephard from roiai.ca (CVE-2026-pending)

References ~~~~~~~~~~ - https://launchpad.net/bugs/2152115 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes ~~~~~ - A CVE request has been filed with MITRE (CAN-2026-2030702). - This is a regression of CVE-2015-5240 (OSSA-2015-018).

-- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203