Junglewise Threat Intelligence

CVE-2026-94572: OpenStack Octavia HAProxy configuration injection in tls_ciphers field

CVE-2026-94572 · Severity: info · Published 2026-09-21

Technologies: OpenStack Octavia. Vendors: OpenStack.

Executive brief

OpenStack Octavia is a load-balancing service that uses HAProxy on Amphora instances to distribute traffic. An authenticated project member can inject arbitrary HAProxy configuration directives by embedding newline characters in the TLS cipher list, potentially achieving remote code execution on the load balancer backend. Only deployments using the Amphora provider are affected.

Technical details

The Amphora provider driver fails to validate control characters (including newlines) in the tls_ciphers field of pools and listeners before writing the value verbatim into HAProxy configuration files via Jinja templates. An authenticated project member with permission to modify a TLS-enabled pool can inject arbitrary HAProxy directives on the server line, such as "check" or "alpn" options, or complete configuration statements. The vulnerability requires project membership and network access to the Octavia API; fixes are available in versions 18.0.1 and later.

Affected products

  • OpenStack Octavia before 18.0.1

Timeline

  • 2026-07-30: disclosed: Bug reported on Launchpad
  • 2026-09-21: advisory: OSSA-2026-039 security advisory published
  • 2026-09-17: patched: Fix released upstream; Debian fix in octavia 18.0.0-4

References

Related threats