Technology · PyPI
nova (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 55 vulnerabilities in nova (PyPI): 0 in the last 7 days and 37 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-32498, was published on 13 July 2026.
- Last 7 days
- 0
- Last 90 days
- 37
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest nova (PyPI) vulnerabilities
- CVE-2024-32498: PYSEC-2026-2493 - OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file accesslowCVSS 3.1EPSS 0.8%
- CVE-2024-40767: PYSEC-2026-1709 - OpenStack Nova vulnerable to unauthorized access to potentially sensitive datalowCVSS 3.1EPSS 0.9%
- CVE-2022-47951: PYSEC-2026-868 - OpenStack Cinder, glance, and Nova vulnerable to Path TraversallowCVSS 3.1EPSS 1.0%
- CVE-2022-37394: PYSEC-2026-882 - OpenStack Nova Changing vnic_type breaks compute service restartlowCVSS 3.1EPSS 0.3%
- CVE-2015-9543: PYSEC-2026-857 - OpenStack Nova can leak consoleauth token into log fileslowCVSS 3.1EPSS 0.4%
- CVE-2013-4278: PYSEC-2026-862 - OpenStack Compute (Nova) Resource limit circumvention in Nova private flavorsinfoEPSS 1.5%
- CVE-2013-4179: PYSEC-2026-875 - OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attackinfoEPSS 2.7%
- CVE-2013-4497: PYSEC-2026-859 - OpenStack Compute Nova Improper Access ControlinfoEPSS 1.8%
- CVE-2013-2096: PYSEC-2026-876 - OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 imagemediumCVSS 4EPSS 0.4%
- CVE-2013-6419: PYSEC-2026-858 - OpenStack Nova Router metadata queries are not restricted by tenantinfoCVSS 0EPSS 1.8%
- CVE-2013-4463: PYSEC-2026-865 - OpenStack Nova denial of service through compressed disk imagesinfoEPSS 0.4%
- CVE-2014-0167: PYSEC-2026-878 - OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requestsmediumCVSS 4EPSS 1.7%
- CVE-2013-4469: PYSEC-2026-860 - OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 imageinfoCVSS 0EPSS 0.4%
- CVE-2015-5162: PYSEC-2026-871 - OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource ConsumptionlowCVSS 3EPSS 3.1%
- CVE-2012-1585: PYSEC-2026-880 - OpenStack Nova Long server names grow nova-api log files significantlyinfoEPSS 2.1%
- CVE-2013-4185: PYSEC-2026-879 - OpenStack Nova Denial of Service in network source security groupsinfoEPSS 2.1%
- CVE-2014-3517: PYSEC-2026-884 - OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityinfoEPSS 1.9%
- CVE-2011-4596: PYSEC-2026-881 - OpenStack Nova Multiple directory traversal vulnerabilitiesinfoEPSS 1.8%
- CVE-2013-2256: PYSEC-2026-866 - OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive informationinfoEPSS 1.8%
- CVE-2015-8749: PYSEC-2026-870 - OpenStack Nova Potential Xen connection password leak via StorageErrorlowCVSS 3EPSS 2.2%
- CVE-2013-6437: PYSEC-2026-874 - OpenStack Nova DoS through ephemeral disk backing filesinfoEPSS 2.0%
- CVE-2015-3241: PYSEC-2026-861 - OpenStack Nova instance migration process does not stop when instance is deletedinfoEPSS 3.5%
- CVE-2015-7713: PYSEC-2026-867 - OpenStack Compute (Nova) allows remote attackers to bypass intended restrictioninfoEPSS 3.7%
- CVE-2014-3708: PYSEC-2026-863 - OpenStack Compute (Nova) Denial of Service vulnerabilityinfoEPSS 2.8%
- CVE-2014-3608: PYSEC-2026-869 - OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of serviceinfoEPSS 1.7%
Most severe nova (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-24708: OpenStack Nova host data destruction via unsafe qemu-img resizehighCVSS 8.2EPSS 0.4%
- CVE-2026-46448: OpenStack Nova scheduler hint injection in server create APImediumCVSS 5.4EPSS 0.5%
- CVE-2012-5625: OpenStack Nova information leak in libvirt LVM-backed instancesmediumCVSS 4.3EPSS 2.0%
- CVE-2014-0167: PYSEC-2026-878 - OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requestsmediumCVSS 4EPSS 1.7%
- CVE-2013-2096: PYSEC-2026-876 - OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 imagemediumCVSS 4EPSS 0.4%
- CVE-2021-3654: PYSEC-2026-693 - Open Redirect in CPython that affects users of OpenStack NovalowCVSS 3.1EPSS 26.8%
- CVE-2013-1838: PYSEC-2013-44 - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota…lowCVSS 3.1EPSS 2.7%
- CVE-2013-7130: PYSEC-2014-111 - The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack…lowCVSS 3.1EPSS 2.4%
- CVE-2013-0335: PYSEC-2013-43 - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to…lowCVSS 3.1EPSS 2.1%
- CVE-2019-14433: PYSEC-2019-191 - An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If…lowCVSS 3.1EPSS 1.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 29 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-nova.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "nova (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-nova, 27 September 2026.