{"schema_version":1,"title":"keystone (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 47 vulnerabilities in keystone (PyPI): 0 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2015-7546, was published on 9 July 2026.","url":"https://junglewise.ai/threats/technologies/keystone","json_url":"https://junglewise.ai/threats/technologies/keystone.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/keystone","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":47,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":16,"last_365_days":23},"latest":[{"cve":"CVE-2015-7546","cvss":3.1,"epss":0.0172,"slug":"cve-2015-7546-openstack-identity-keystone-and-keystonemiddleware-insufficiently","title":"PYSEC-2026-2549 - OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:45.704524+00:00","url":"https://junglewise.ai/threats/cve-2015-7546-openstack-identity-keystone-and-keystonemiddleware-insufficiently"},{"cve":"CVE-2025-65073","cvss":3.1,"epss":0.0023,"slug":"cve-2025-65073-openstack-keystone-allows-v3-ec2tokens-or-v3-s3tokens-request","title":"PYSEC-2026-1490 - OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:10.401718+00:00","url":"https://junglewise.ai/threats/cve-2025-65073-openstack-keystone-allows-v3-ec2tokens-or-v3-s3tokens-request"},{"cve":"CVE-2021-38155","cvss":3.1,"epss":0.0248,"slug":"cve-2021-38155-openstack-keystone-allows-information-disclosure-during-account","title":"PYSEC-2026-830 - OpenStack Keystone allows information disclosure during account locking","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.999306+00:00","url":"https://junglewise.ai/threats/cve-2021-38155-openstack-keystone-allows-information-disclosure-during-account"},{"cve":"CVE-2013-4477","epss":0.0045,"slug":"cve-2013-4477-openstack-identity-keystone-privilege-escalation-vulnerability","title":"PYSEC-2026-831 - OpenStack Identity Keystone Privilege Escalation vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.59662+00:00","url":"https://junglewise.ai/threats/cve-2013-4477-openstack-identity-keystone-privilege-escalation-vulnerability"},{"cve":"CVE-2012-4413","epss":0.019,"slug":"cve-2012-4413-openstack-keystone-does-not-invalidate-existing-tokens-when","title":"PYSEC-2026-833 - OpenStack Keystone does not invalidate existing tokens when granting or revoking roles","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:24.535889+00:00","url":"https://junglewise.ai/threats/cve-2012-4413-openstack-keystone-does-not-invalidate-existing-tokens-when"},{"cve":"CVE-2012-4456","epss":0.04,"slug":"cve-2012-4456-openstack-keystone-improper-authentication-vulnerability","title":"PYSEC-2026-832 - OpenStack Keystone Improper Authentication vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.962802+00:00","url":"https://junglewise.ai/threats/cve-2012-4456-openstack-keystone-improper-authentication-vulnerability"},{"cve":"CVE-2012-4457","epss":0.0229,"slug":"cve-2012-4457-openstack-keystone-token-authorization-for-a-user-in-a-disabled","title":"PYSEC-2026-834 - OpenStack Keystone Token authorization for a user in a disabled tenant is allowed","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.920291+00:00","url":"https://junglewise.ai/threats/cve-2012-4457-openstack-keystone-token-authorization-for-a-user-in-a-disabled"},{"cve":"CVE-2014-3621","epss":0.0213,"slug":"cve-2014-3621-openstack-identity-keystone-exposure-of-sensitive-information","title":"PYSEC-2026-653 - OpenStack Identity Keystone Exposure of Sensitive Information","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.972537+00:00","url":"https://junglewise.ai/threats/cve-2014-3621-openstack-identity-keystone-exposure-of-sensitive-information"},{"cve":"CVE-2014-0204","epss":0.014,"slug":"cve-2014-0204-openstack-identity-keystone-improper-privilege-management","title":"PYSEC-2026-654 - OpenStack Identity Keystone Improper Privilege Management","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.90891+00:00","url":"https://junglewise.ai/threats/cve-2014-0204-openstack-identity-keystone-improper-privilege-management"},{"cve":"CVE-2015-3646","epss":0.0288,"slug":"cve-2015-3646-openstack-keystone-logs-passwords","title":"PYSEC-2026-655 - OpenStack Keystone Logs Passwords","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.853843+00:00","url":"https://junglewise.ai/threats/cve-2015-3646-openstack-keystone-logs-passwords"},{"cve":"CVE-2014-3476","cvss":6.8,"epss":0.0233,"slug":"cve-2014-3476-openstack-keystone-privilege-escalation-via-trust-chaining","title":"PYSEC-2026-649 - OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.805823+00:00","url":"https://junglewise.ai/threats/cve-2014-3476-openstack-keystone-privilege-escalation-via-trust-chaining"},{"cve":"CVE-2013-2014","epss":0.0327,"slug":"cve-2013-2014-openstack-identity-keystone-denial-of-service","title":"PYSEC-2026-651 - OpenStack Identity (Keystone) Denial of Service","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.743769+00:00","url":"https://junglewise.ai/threats/cve-2013-2014-openstack-identity-keystone-denial-of-service"},{"cve":"CVE-2013-0282","epss":0.0176,"slug":"cve-2013-0282-openstack-keystone-allows-context-dependent-attackers-to-bypass","title":"PYSEC-2026-652 - OpenStack Keystone allows context-dependent attackers to bypass access restrictions","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:22.090672+00:00","url":"https://junglewise.ai/threats/cve-2013-0282-openstack-keystone-allows-context-dependent-attackers-to-bypass"},{"cve":"CVE-2013-0270","cvss":3.1,"epss":0.0317,"slug":"cve-2013-0270-openstack-keystone-denial-of-service-vulnerability-via-a-large","title":"PYSEC-2026-650 - OpenStack Keystone Denial of Service vulnerability via a large HTTP request","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:22.017502+00:00","url":"https://junglewise.ai/threats/cve-2013-0270-openstack-keystone-denial-of-service-vulnerability-via-a-large"},{"cve":"CVE-2013-2255","cvss":3.1,"epss":0.0097,"slug":"cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper","title":"PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate Validation","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.847931+00:00","url":"https://junglewise.ai/threats/cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper"},{"cve":"CVE-2021-3563","cvss":3.1,"epss":0.0175,"slug":"cve-2021-3563-openstack-keystone-incorrect-authorization-vulnerability","title":"PYSEC-2026-370 - Openstack Keystone Incorrect Authorization vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:33.812046+00:00","url":"https://junglewise.ai/threats/cve-2021-3563-openstack-keystone-incorrect-authorization-vulnerability"},{"cve":"CVE-2026-44394","cvss":6,"epss":0.0032,"slug":"cve-2026-44394-openstack-keystone-authentication-expiry-bypass-in-federated","title":"OpenStack Keystone authentication expiry bypass in federated token rescoping","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:38.223+00:00","url":"https://junglewise.ai/threats/cve-2026-44394-openstack-keystone-authentication-expiry-bypass-in-federated"},{"cve":"CVE-2026-43000","cvss":6,"epss":0.0043,"slug":"cve-2026-43000-openstack-keystone-privilege-escalation-via-trust-delegation","title":"OpenStack Keystone privilege escalation via trust delegation","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.773+00:00","url":"https://junglewise.ai/threats/cve-2026-43000-openstack-keystone-privilege-escalation-via-trust-delegation"},{"cve":"CVE-2026-42999","cvss":6,"epss":0.0042,"slug":"cve-2026-42999-openstack-keystone-rbac-policy-bypass-via-json-request-body","title":"OpenStack Keystone RBAC policy bypass via JSON request body injection","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.63+00:00","url":"https://junglewise.ai/threats/cve-2026-42999-openstack-keystone-rbac-policy-bypass-via-json-request-body"},{"cve":"CVE-2026-42998","cvss":6,"epss":0.004,"slug":"cve-2026-42998-openstack-keystone-user-impersonation-in-application-credentials","title":"OpenStack Keystone User Impersonation in Application Credentials","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.483+00:00","url":"https://junglewise.ai/threats/cve-2026-42998-openstack-keystone-user-impersonation-in-application-credentials"},{"cve":"CVE-2026-43001","cvss":7.9,"epss":0.0059,"slug":"cve-2026-43001-openstack-keystone-authorization-bypass-in-ec2-credential","title":"OpenStack Keystone authorization bypass in EC2 credential creation","severity":"high","exploited":false,"published_at":"2026-05-01T09:16:17.273+00:00","url":"https://junglewise.ai/threats/cve-2026-43001-openstack-keystone-authorization-bypass-in-ec2-credential"},{"cve":"CVE-2026-40683","cvss":7.7,"epss":0.0037,"slug":"cve-2026-40683-openstack-keystone-incorrect-ldap-user-status-handling","title":"OpenStack Keystone incorrect LDAP user status handling","severity":"high","exploited":false,"published_at":"2026-04-14T20:16:48.203+00:00","url":"https://junglewise.ai/threats/cve-2026-40683-openstack-keystone-incorrect-ldap-user-status-handling"},{"cve":"CVE-2026-33551","cvss":3.5,"epss":0.0033,"slug":"cve-2026-33551-openstack-keystone-authorization-bypass-in-ec2-credential","title":"OpenStack Keystone authorization bypass in EC2 credential creation","severity":"low","exploited":false,"published_at":"2026-04-10T03:16:02.723+00:00","url":"https://junglewise.ai/threats/cve-2026-33551-openstack-keystone-authorization-bypass-in-ec2-credential"},{"slug":"keystone-cross-site-scripting-9990301e","title":"Keystone cross-site scripting","severity":"info","exploited":false,"published_at":"2020-08-20T17:21:46+00:00","url":"https://junglewise.ai/threats/keystone-cross-site-scripting-9990301e"},{"cve":"CVE-2020-12692","cvss":3.1,"epss":0.0071,"slug":"cve-2020-12692-openstack-keystone-does-not-check-signature-ttl-of-the-ec2","title":"PYSEC-2020-56 - An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4","severity":"low","exploited":false,"published_at":"2020-05-07T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-12692-openstack-keystone-does-not-check-signature-ttl-of-the-ec2"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"keystone (PyPI)","slug":"keystone","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://keystone.openstack.org/","repo_url":"https://github.com/openstack/keystone","description":"An open-source identity service used to provide authentication and authorization for the OpenStack ecosystem.","url":"https://junglewise.ai/threats/technologies/keystone"},"most_severe":[{"cve":"CVE-2026-43001","cvss":7.9,"epss":0.0059,"slug":"cve-2026-43001-openstack-keystone-authorization-bypass-in-ec2-credential","title":"OpenStack Keystone authorization bypass in EC2 credential creation","severity":"high","exploited":false,"published_at":"2026-05-01T09:16:17.273+00:00","url":"https://junglewise.ai/threats/cve-2026-43001-openstack-keystone-authorization-bypass-in-ec2-credential"},{"cve":"CVE-2026-40683","cvss":7.7,"epss":0.0037,"slug":"cve-2026-40683-openstack-keystone-incorrect-ldap-user-status-handling","title":"OpenStack Keystone incorrect LDAP user status handling","severity":"high","exploited":false,"published_at":"2026-04-14T20:16:48.203+00:00","url":"https://junglewise.ai/threats/cve-2026-40683-openstack-keystone-incorrect-ldap-user-status-handling"},{"cve":"CVE-2026-43000","cvss":6,"epss":0.0043,"slug":"cve-2026-43000-openstack-keystone-privilege-escalation-via-trust-delegation","title":"OpenStack Keystone privilege escalation via trust delegation","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.773+00:00","url":"https://junglewise.ai/threats/cve-2026-43000-openstack-keystone-privilege-escalation-via-trust-delegation"},{"cve":"CVE-2026-42999","cvss":6,"epss":0.0042,"slug":"cve-2026-42999-openstack-keystone-rbac-policy-bypass-via-json-request-body","title":"OpenStack Keystone RBAC policy bypass via JSON request body injection","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.63+00:00","url":"https://junglewise.ai/threats/cve-2026-42999-openstack-keystone-rbac-policy-bypass-via-json-request-body"},{"cve":"CVE-2026-42998","cvss":6,"epss":0.004,"slug":"cve-2026-42998-openstack-keystone-user-impersonation-in-application-credentials","title":"OpenStack Keystone User Impersonation in Application Credentials","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:37.483+00:00","url":"https://junglewise.ai/threats/cve-2026-42998-openstack-keystone-user-impersonation-in-application-credentials"},{"cve":"CVE-2026-44394","cvss":6,"epss":0.0032,"slug":"cve-2026-44394-openstack-keystone-authentication-expiry-bypass-in-federated","title":"OpenStack Keystone authentication expiry bypass in federated token rescoping","severity":"medium","exploited":false,"published_at":"2026-05-28T19:16:38.223+00:00","url":"https://junglewise.ai/threats/cve-2026-44394-openstack-keystone-authentication-expiry-bypass-in-federated"},{"cve":"CVE-2026-33551","cvss":3.5,"epss":0.0033,"slug":"cve-2026-33551-openstack-keystone-authorization-bypass-in-ec2-credential","title":"OpenStack Keystone authorization bypass in EC2 credential creation","severity":"low","exploited":false,"published_at":"2026-04-10T03:16:02.723+00:00","url":"https://junglewise.ai/threats/cve-2026-33551-openstack-keystone-authorization-bypass-in-ec2-credential"},{"cve":"CVE-2020-12691","cvss":3.1,"epss":0.0492,"slug":"cve-2020-12691-openstack-keystone-v3-credentials-endpoint-policy-logic-allows-to","title":"PYSEC-2020-55 - An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves","severity":"low","exploited":false,"published_at":"2020-05-07T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-12691-openstack-keystone-v3-credentials-endpoint-policy-logic-allows-to"},{"cve":"CVE-2013-0270","cvss":3.1,"epss":0.0317,"slug":"cve-2013-0270-openstack-keystone-denial-of-service-vulnerability-via-a-large","title":"PYSEC-2026-650 - OpenStack Keystone Denial of Service vulnerability via a large HTTP request","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:22.017502+00:00","url":"https://junglewise.ai/threats/cve-2013-0270-openstack-keystone-denial-of-service-vulnerability-via-a-large"},{"cve":"CVE-2014-2828","cvss":3.1,"epss":0.0316,"slug":"cve-2014-2828-openstack-identity-keystone-dos-through-v3-api-authentication","title":"PYSEC-2014-106 - The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denia","severity":"low","exploited":false,"published_at":"2014-04-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-2828-openstack-identity-keystone-dos-through-v3-api-authentication"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}