{"schema_version":1,"title":"neutron (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in neutron (PyPI): 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-53916, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-neutron","json_url":"https://junglewise.ai/threats/technologies/pypi-neutron.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-neutron","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":21,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":12},"latest":[{"cve":"CVE-2024-53916","cvss":3.1,"epss":0.0071,"slug":"cve-2024-53916-openstack-neutron-can-use-an-incorrect-id-during-policy","title":"PYSEC-2026-1693 - OpenStack Neutron can use an incorrect ID during policy enforcement","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:45.6628+00:00","url":"https://junglewise.ai/threats/cve-2024-53916-openstack-neutron-can-use-an-incorrect-id-during-policy"},{"cve":"CVE-2023-3637","cvss":3.1,"epss":0.0131,"slug":"cve-2023-3637-denial-of-service-in-neutron","title":"PYSEC-2026-1694 - Denial of service in neutron","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:21.327812+00:00","url":"https://junglewise.ai/threats/cve-2023-3637-denial-of-service-in-neutron"},{"cve":"CVE-2022-3277","cvss":3.1,"epss":0.0107,"slug":"cve-2022-3277-openstack-neutron-uncontrolled-resource-consumption-flaw","title":"PYSEC-2026-855 - openstack-neutron uncontrolled resource consumption flaw","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:28.235305+00:00","url":"https://junglewise.ai/threats/cve-2022-3277-openstack-neutron-uncontrolled-resource-consumption-flaw"},{"cve":"CVE-2014-0056","epss":0.0145,"slug":"cve-2014-0056-openstack-neutron-improper-authentication-vulnerability","title":"PYSEC-2026-851 - OpenStack Neutron Improper Authentication vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.034481+00:00","url":"https://junglewise.ai/threats/cve-2014-0056-openstack-neutron-improper-authentication-vulnerability"},{"cve":"CVE-2015-5240","epss":0.0097,"slug":"cve-2015-5240-openstack-neutron-race-condition-vulnerability","title":"PYSEC-2026-853 - OpenStack Neutron Race condition vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.638146+00:00","url":"https://junglewise.ai/threats/cve-2015-5240-openstack-neutron-race-condition-vulnerability"},{"cve":"CVE-2016-5363","cvss":3,"epss":0.0327,"slug":"cve-2016-5363-openstack-neutron-intended-mac-spoofing-protection-mechanism","title":"PYSEC-2026-852 - OpenStack Neutron Intended MAC-spoofing protection mechanism bypass","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:25.500474+00:00","url":"https://junglewise.ai/threats/cve-2016-5363-openstack-neutron-intended-mac-spoofing-protection-mechanism"},{"cve":"CVE-2016-5362","cvss":3,"epss":0.0344,"slug":"cve-2016-5362-openstack-neutron-allows-remote-attackers-to-bypass-an-intended","title":"PYSEC-2026-854 - OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:23.728206+00:00","url":"https://junglewise.ai/threats/cve-2016-5362-openstack-neutron-allows-remote-attackers-to-bypass-an-intended"},{"cve":"CVE-2017-7543","cvss":3,"epss":0.0186,"slug":"cve-2017-7543-openstack-neutron-race-condition-vulnerability","title":"PYSEC-2026-686 - OpenStack Neutron Race Condition vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:22.484803+00:00","url":"https://junglewise.ai/threats/cve-2017-7543-openstack-neutron-race-condition-vulnerability"},{"cve":"CVE-2013-2255","cvss":3.1,"epss":0.0097,"slug":"cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper","title":"PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate Validation","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.847931+00:00","url":"https://junglewise.ai/threats/cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper"},{"cve":"CVE-2015-8914","cvss":3,"epss":0.0428,"slug":"cve-2015-8914-openstack-neutron-allows-remote-attackers-to-bypass-an-intended","title":"PYSEC-2026-431 - OpenStack Neutron allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.602905+00:00","url":"https://junglewise.ai/threats/cve-2015-8914-openstack-neutron-allows-remote-attackers-to-bypass-an-intended"},{"cve":"CVE-2026-50266","cvss":3.1,"epss":0.0038,"slug":"cve-2026-50266-openstack-neutron-rbac-policy-bypass-in-shared-network-ports","title":"OpenStack Neutron RBAC policy bypass in shared network ports","severity":"low","exploited":false,"published_at":"2026-06-04T17:16:33.517+00:00","url":"https://junglewise.ai/threats/cve-2026-50266-openstack-neutron-rbac-policy-bypass-in-shared-network-ports"},{"cve":"CVE-2026-49299","cvss":4,"epss":0.0043,"slug":"cve-2026-49299-openstack-neutron-incorrect-authorization-in-tagging-controller","title":"OpenStack Neutron incorrect authorization in tagging controller","severity":"medium","exploited":false,"published_at":"2026-05-28T22:17:02.093+00:00","url":"https://junglewise.ai/threats/cve-2026-49299-openstack-neutron-incorrect-authorization-in-tagging-controller"},{"cve":"CVE-2015-3221","cvss":0,"epss":0.1143,"slug":"cve-2015-3221-openstack-neutron-denial-of-service-in-iptables-firewall-driver","title":"OpenStack Neutron denial of service in IPTables firewall driver","severity":"medium","exploited":false,"published_at":"2022-05-14T02:19:50+00:00","url":"https://junglewise.ai/threats/cve-2015-3221-openstack-neutron-denial-of-service-in-iptables-firewall-driver"},{"cve":"CVE-2021-40797","cvss":3.1,"epss":0.0177,"slug":"cve-2021-40797-openstack-neutron-denial-of-service-vulnerability","title":"PYSEC-2021-329 - An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making A","severity":"low","exploited":false,"published_at":"2021-09-08T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40797-openstack-neutron-denial-of-service-vulnerability"},{"cve":"CVE-2021-40085","cvss":3.1,"epss":0.0183,"slug":"cve-2021-40085-openstack-neutron-vulnerable-to-authenticated-attackers","title":"PYSEC-2021-361 - An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfig","severity":"low","exploited":false,"published_at":"2021-08-31T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40085-openstack-neutron-vulnerable-to-authenticated-attackers"},{"cve":"CVE-2021-38598","cvss":3.1,"epss":0.0122,"slug":"cve-2021-38598-openstack-neutron-vulnerable-to-hardware-address-impersonation","title":"PYSEC-2021-360 - OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab","severity":"low","exploited":false,"published_at":"2021-08-23T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-38598-openstack-neutron-vulnerable-to-hardware-address-impersonation"},{"cve":"CVE-2021-20267","cvss":3.1,"epss":0.0102,"slug":"cve-2021-20267-openstack-neutron-has-insufficient-verification-of-ipv6-addresses","title":"PYSEC-2021-136 - A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a se","severity":"low","exploited":false,"published_at":"2021-05-28T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-20267-openstack-neutron-has-insufficient-verification-of-ipv6-addresses"},{"cve":"CVE-2019-10876","cvss":3,"epss":0.0173,"slug":"cve-2019-10876-openstack-neutron-overlapping-security-group-rules-prevents","title":"PYSEC-2019-189 - An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups","severity":"low","exploited":false,"published_at":"2019-04-05T05:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-10876-openstack-neutron-overlapping-security-group-rules-prevents"},{"cve":"CVE-2019-9735","cvss":3,"epss":0.0371,"slug":"cve-2019-9735-openstack-neutron-s-unsupported-dport-option-prevents-applying","title":"PYSEC-2019-190 - An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x","severity":"low","exploited":false,"published_at":"2019-03-13T02:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-9735-openstack-neutron-s-unsupported-dport-option-prevents-applying"},{"cve":"CVE-2018-14635","cvss":3,"epss":0.0253,"slug":"cve-2018-14635-opensstack-neutron-denial-of-service-vulnerability","title":"PYSEC-2018-93 - When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassi","severity":"low","exploited":false,"published_at":"2018-09-10T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-14635-opensstack-neutron-denial-of-service-vulnerability"},{"cve":"CVE-2018-14636","cvss":3,"epss":0.0117,"slug":"cve-2018-14636-openstack-neutron-vulnerable-to-eavesdropping-on-private-traffic","title":"PYSEC-2018-94 - Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended","severity":"low","exploited":false,"published_at":"2018-09-10T19:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-14636-openstack-neutron-vulnerable-to-eavesdropping-on-private-traffic"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"neutron (PyPI)","slug":"pypi-neutron","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/pypi-neutron"},"most_severe":[{"cve":"CVE-2026-49299","cvss":4,"epss":0.0043,"slug":"cve-2026-49299-openstack-neutron-incorrect-authorization-in-tagging-controller","title":"OpenStack Neutron incorrect authorization in tagging controller","severity":"medium","exploited":false,"published_at":"2026-05-28T22:17:02.093+00:00","url":"https://junglewise.ai/threats/cve-2026-49299-openstack-neutron-incorrect-authorization-in-tagging-controller"},{"cve":"CVE-2015-3221","cvss":0,"epss":0.1143,"slug":"cve-2015-3221-openstack-neutron-denial-of-service-in-iptables-firewall-driver","title":"OpenStack Neutron denial of service in IPTables firewall driver","severity":"medium","exploited":false,"published_at":"2022-05-14T02:19:50+00:00","url":"https://junglewise.ai/threats/cve-2015-3221-openstack-neutron-denial-of-service-in-iptables-firewall-driver"},{"cve":"CVE-2021-40085","cvss":3.1,"epss":0.0183,"slug":"cve-2021-40085-openstack-neutron-vulnerable-to-authenticated-attackers","title":"PYSEC-2021-361 - An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfig","severity":"low","exploited":false,"published_at":"2021-08-31T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40085-openstack-neutron-vulnerable-to-authenticated-attackers"},{"cve":"CVE-2021-40797","cvss":3.1,"epss":0.0177,"slug":"cve-2021-40797-openstack-neutron-denial-of-service-vulnerability","title":"PYSEC-2021-329 - An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making A","severity":"low","exploited":false,"published_at":"2021-09-08T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-40797-openstack-neutron-denial-of-service-vulnerability"},{"cve":"CVE-2023-3637","cvss":3.1,"epss":0.0131,"slug":"cve-2023-3637-denial-of-service-in-neutron","title":"PYSEC-2026-1694 - Denial of service in neutron","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:21.327812+00:00","url":"https://junglewise.ai/threats/cve-2023-3637-denial-of-service-in-neutron"},{"cve":"CVE-2021-38598","cvss":3.1,"epss":0.0122,"slug":"cve-2021-38598-openstack-neutron-vulnerable-to-hardware-address-impersonation","title":"PYSEC-2021-360 - OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab","severity":"low","exploited":false,"published_at":"2021-08-23T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-38598-openstack-neutron-vulnerable-to-hardware-address-impersonation"},{"cve":"CVE-2022-3277","cvss":3.1,"epss":0.0107,"slug":"cve-2022-3277-openstack-neutron-uncontrolled-resource-consumption-flaw","title":"PYSEC-2026-855 - openstack-neutron uncontrolled resource consumption flaw","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:28.235305+00:00","url":"https://junglewise.ai/threats/cve-2022-3277-openstack-neutron-uncontrolled-resource-consumption-flaw"},{"cve":"CVE-2021-20267","cvss":3.1,"epss":0.0102,"slug":"cve-2021-20267-openstack-neutron-has-insufficient-verification-of-ipv6-addresses","title":"PYSEC-2021-136 - A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a se","severity":"low","exploited":false,"published_at":"2021-05-28T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-20267-openstack-neutron-has-insufficient-verification-of-ipv6-addresses"},{"cve":"CVE-2013-2255","cvss":3.1,"epss":0.0097,"slug":"cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper","title":"PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate Validation","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.847931+00:00","url":"https://junglewise.ai/threats/cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper"},{"cve":"CVE-2024-53916","cvss":3.1,"epss":0.0071,"slug":"cve-2024-53916-openstack-neutron-can-use-an-incorrect-id-during-policy","title":"PYSEC-2026-1693 - OpenStack Neutron can use an incorrect ID during policy enforcement","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:45.6628+00:00","url":"https://junglewise.ai/threats/cve-2024-53916-openstack-neutron-can-use-an-incorrect-id-during-policy"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}