Junglewise Threat Intelligence

CVE-2026-59654: Apache CloudStack resource leak in scoped global configuration

CVE-2026-59654 · Severity: high · CVSS 7.5 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is a cloud management platform used to orchestrate and manage virtualized data centers. A resource leak in its scoped global configuration functionality can cause the management server to accumulate unreleased resources over time, eventually leading to service degradation or outages that impact cloud operations.

Technical details

The vulnerability is a resource leak (missing release of resource after effective lifetime) in Apache CloudStack's scoped global configuration functionality, affecting modules such as Quota and Host-HA. The issue resides in the management server code and is triggered during normal configuration processing. An attacker with network access to the management server can exploit this by repeatedly triggering the affected configuration logic to exhaust server resources, resulting in denial of service. The vulnerability has been patched in versions 4.20.3.1, 4.22.1.1, and later.

Affected products

  • Apache CloudStack 4.7.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fixed in versions 4.20.3.1, 4.22.1.1 and later

References

Related threats