Executive brief
OpenStack Octavia is a load-balancing service used by cloud operators. An authenticated project member can inject arbitrary HAProxy configuration directives through the L7 policy redirect_url field, allowing them to alter load balancer behavior, inject malicious headers, or execute commands on the underlying Amphora virtual machine. Only deployments using the Amphora provider are affected.
Technical details
The Amphora provider driver in Octavia fails to sanitize control characters (including newlines) in the L7 policy redirect_url field before writing it into HAProxy configuration files. Although the RFC 3986 URL validator percent-encodes control characters before structural validation, the raw unencoded value is stored and interpolated directly into Jinja2 templates, allowing an authenticated project owner to break out of the URL context and inject arbitrary HAProxy directives. An attacker can override HTTP response codes, inject headers, or add new configuration blocks.
Affected products
- OpenStack Octavia before 18.0.1
Timeline
- 2026-09-21: disclosed
- 2026-09-17: patched: Fixed in octavia 18.0.0-4 (Debian)