Technology · PyPI
keystone (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 47 vulnerabilities in keystone (PyPI): 0 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2015-7546, was published on 9 July 2026.
- Last 7 days
- 0
- Last 90 days
- 16
- Critical, all time
- 0
- Exploited in the wild
- 0
About keystone (PyPI)
An open-source identity service used to provide authentication and authorization for the OpenStack ecosystem.
Latest keystone (PyPI) vulnerabilities
- CVE-2015-7546: PYSEC-2026-2549 - OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected CredentialslowCVSS 3.1EPSS 1.7%
- CVE-2025-65073: PYSEC-2026-1490 - OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide…lowCVSS 3.1EPSS 0.2%
- CVE-2021-38155: PYSEC-2026-830 - OpenStack Keystone allows information disclosure during account lockinglowCVSS 3.1EPSS 2.5%
- CVE-2013-4477: PYSEC-2026-831 - OpenStack Identity Keystone Privilege Escalation vulnerabilityinfoEPSS 0.4%
- CVE-2012-4413: PYSEC-2026-833 - OpenStack Keystone does not invalidate existing tokens when granting or revoking rolesinfoEPSS 1.9%
- CVE-2012-4456: PYSEC-2026-832 - OpenStack Keystone Improper Authentication vulnerabilityinfoEPSS 4.0%
- CVE-2012-4457: PYSEC-2026-834 - OpenStack Keystone Token authorization for a user in a disabled tenant is allowedinfoEPSS 2.3%
- CVE-2014-3621: PYSEC-2026-653 - OpenStack Identity Keystone Exposure of Sensitive InformationinfoEPSS 2.1%
- CVE-2014-0204: PYSEC-2026-654 - OpenStack Identity Keystone Improper Privilege ManagementinfoEPSS 1.4%
- CVE-2015-3646: PYSEC-2026-655 - OpenStack Keystone Logs PasswordsinfoEPSS 2.9%
- CVE-2014-3476: PYSEC-2026-649 - OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilegeinfoCVSS 6.8EPSS 2.3%
- CVE-2013-2014: PYSEC-2026-651 - OpenStack Identity (Keystone) Denial of ServiceinfoEPSS 3.3%
- CVE-2013-0282: PYSEC-2026-652 - OpenStack Keystone allows context-dependent attackers to bypass access restrictionsinfoEPSS 1.8%
- CVE-2013-0270: PYSEC-2026-650 - OpenStack Keystone Denial of Service vulnerability via a large HTTP requestlowCVSS 3.1EPSS 3.2%
- CVE-2013-2255: PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate ValidationlowCVSS 3.1EPSS 1.0%
- CVE-2021-3563: PYSEC-2026-370 - Openstack Keystone Incorrect Authorization vulnerabilitylowCVSS 3.1EPSS 1.8%
- CVE-2026-44394: OpenStack Keystone authentication expiry bypass in federated token rescopingmediumCVSS 6EPSS 0.3%
- CVE-2026-43000: OpenStack Keystone privilege escalation via trust delegationmediumCVSS 6EPSS 0.4%
- CVE-2026-42999: OpenStack Keystone RBAC policy bypass via JSON request body injectionmediumCVSS 6EPSS 0.4%
- CVE-2026-42998: OpenStack Keystone User Impersonation in Application CredentialsmediumCVSS 6EPSS 0.4%
- CVE-2026-43001: OpenStack Keystone authorization bypass in EC2 credential creationhighCVSS 7.9EPSS 0.6%
- CVE-2026-40683: OpenStack Keystone incorrect LDAP user status handlinghighCVSS 7.7EPSS 0.4%
- CVE-2026-33551: OpenStack Keystone authorization bypass in EC2 credential creationlowCVSS 3.5EPSS 0.3%
- Keystone cross-site scriptinginfo
- CVE-2020-12692: PYSEC-2020-56 - An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a…lowCVSS 3.1EPSS 0.7%
Most severe keystone (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43001: OpenStack Keystone authorization bypass in EC2 credential creationhighCVSS 7.9EPSS 0.6%
- CVE-2026-40683: OpenStack Keystone incorrect LDAP user status handlinghighCVSS 7.7EPSS 0.4%
- CVE-2026-43000: OpenStack Keystone privilege escalation via trust delegationmediumCVSS 6EPSS 0.4%
- CVE-2026-42999: OpenStack Keystone RBAC policy bypass via JSON request body injectionmediumCVSS 6EPSS 0.4%
- CVE-2026-42998: OpenStack Keystone User Impersonation in Application CredentialsmediumCVSS 6EPSS 0.4%
- CVE-2026-44394: OpenStack Keystone authentication expiry bypass in federated token rescopingmediumCVSS 6EPSS 0.3%
- CVE-2026-33551: OpenStack Keystone authorization bypass in EC2 credential creationlowCVSS 3.5EPSS 0.3%
- CVE-2020-12691: PYSEC-2020-55 - An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create…lowCVSS 3.1EPSS 4.9%
- CVE-2013-0270: PYSEC-2026-650 - OpenStack Keystone Denial of Service vulnerability via a large HTTP requestlowCVSS 3.1EPSS 3.2%
- CVE-2014-2828: PYSEC-2014-106 - The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows…lowCVSS 3.1EPSS 3.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 9 | 0 | |
| 6 Jul 2026 | 7 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/keystone.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "keystone (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/keystone, 26 September 2026.