Junglewise Threat Intelligence

CVE-2026-94571: OpenStack Octavia HAProxy configuration injection via L7 redirect URL

CVE-2026-94571 · Severity: info · Published 2026-09-21

Technologies: OpenStack Octavia. Vendors: OpenStack.

Executive brief

OpenStack Octavia is a load-balancing service used by cloud operators. An authenticated project member can inject arbitrary HAProxy configuration directives through the L7 policy redirect_url field, allowing them to alter load balancer behavior, inject malicious headers, or execute commands on the underlying Amphora virtual machine. Only deployments using the Amphora provider are affected.

Technical details

The Amphora provider driver in Octavia fails to sanitize control characters (including newlines) in the L7 policy redirect_url field before writing it into HAProxy configuration files. Although the RFC 3986 URL validator percent-encodes control characters before structural validation, the raw unencoded value is stored and interpolated directly into Jinja2 templates, allowing an authenticated project owner to break out of the URL context and inject arbitrary HAProxy directives. An attacker can override HTTP response codes, inject headers, or add new configuration blocks.

Affected products

  • OpenStack Octavia before 18.0.1

Timeline

  • 2026-09-21: disclosed
  • 2026-09-17: patched: Fixed in octavia 18.0.0-4 (Debian)

References

Related threats