Executive brief
OpenStack Swift, a widely used cloud storage system, contains a security flaw in its proxy server component. An authorized user with write access can trick the system into sending internal data to an external server they control. This could lead to the exposure of sensitive technical details about the storage infrastructure or the creation of 'ghost' files that disrupt data organization.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the OpenStack Swift proxy-server because it fails to strip internal update headers (such as X-Container-Host and X-Delete-At-Host) from client requests. An authenticated attacker with write permissions can inject these headers to redirect container update requests from internal object servers to an external, attacker-controlled host. This exploit can leak sensitive cluster metadata, including storage policy indexes, partition mappings, and encryption initialization vectors. It also allows for the creation of 'ghost listings' via the shard-range redirect mechanism. The issue is fixed in versions 2.35.3, 2.36.2, and 2.37.2.
Affected products
- OpenStack Swift >=2.0.0 <2.35.3, >=2.36.0 <2.36.2, >=2.37.0 <2.37.2
Timeline
- 2026-04-24: disclosed: Bug reported to OpenStack by Tim Shephard
- 2026-06-23: advisory: OSSA-2026-024 published
- 2026-06-23: patched: Fixes released in multiple branches