{"schema_version":1,"title":"nova (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 55 vulnerabilities in nova (PyPI): 0 in the last 7 days and 36 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-32498, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-nova","json_url":"https://junglewise.ai/threats/technologies/pypi-nova.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-nova","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":55,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":36,"last_365_days":39},"latest":[{"cve":"CVE-2024-32498","cvss":3.1,"epss":0.0084,"slug":"cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file","title":"PYSEC-2026-2493 - OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.3204+00:00","url":"https://junglewise.ai/threats/cve-2024-32498-openstack-cinder-glance-and-nova-vulnerable-to-arbitrary-file"},{"cve":"CVE-2024-40767","cvss":3.1,"epss":0.0094,"slug":"cve-2024-40767-openstack-nova-vulnerable-to-unauthorized-access-to-potentially","title":"PYSEC-2026-1709 - OpenStack Nova vulnerable to unauthorized access to potentially sensitive data","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:37.675804+00:00","url":"https://junglewise.ai/threats/cve-2024-40767-openstack-nova-vulnerable-to-unauthorized-access-to-potentially"},{"cve":"CVE-2022-47951","cvss":3.1,"epss":0.0103,"slug":"cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal","title":"PYSEC-2026-868 - OpenStack Cinder, glance, and Nova vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:27.389246+00:00","url":"https://junglewise.ai/threats/cve-2022-47951-openstack-cinder-glance-and-nova-vulnerable-to-path-traversal"},{"cve":"CVE-2022-37394","cvss":3.1,"epss":0.0031,"slug":"cve-2022-37394-openstack-nova-changing-vnic-type-breaks-compute-service-restart","title":"PYSEC-2026-882 - OpenStack Nova Changing vnic_type breaks compute service restart","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:31.64439+00:00","url":"https://junglewise.ai/threats/cve-2022-37394-openstack-nova-changing-vnic-type-breaks-compute-service-restart"},{"cve":"CVE-2015-9543","cvss":3.1,"epss":0.0041,"slug":"cve-2015-9543-openstack-nova-consoleauth-token-leak-into-log-files","title":"PYSEC-2026-857 - OpenStack Nova can leak consoleauth token into log files","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.48164+00:00","url":"https://junglewise.ai/threats/cve-2015-9543-openstack-nova-consoleauth-token-leak-into-log-files"},{"cve":"CVE-2013-4278","epss":0.0151,"slug":"cve-2013-4278-openstack-compute-nova-resource-limit-circumvention-in-nova","title":"PYSEC-2026-862 - OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:27.04613+00:00","url":"https://junglewise.ai/threats/cve-2013-4278-openstack-compute-nova-resource-limit-circumvention-in-nova"},{"cve":"CVE-2013-4179","epss":0.0273,"slug":"cve-2013-4179-openstack-compute-nova-vulnerable-to-denial-of-service-via-xml","title":"PYSEC-2026-875 - OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.993196+00:00","url":"https://junglewise.ai/threats/cve-2013-4179-openstack-compute-nova-vulnerable-to-denial-of-service-via-xml"},{"cve":"CVE-2013-4497","epss":0.0182,"slug":"cve-2013-4497-openstack-compute-nova-improper-access-control-in-xenapi-backend","title":"PYSEC-2026-859 - OpenStack Compute Nova Improper Access Control","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.876718+00:00","url":"https://junglewise.ai/threats/cve-2013-4497-openstack-compute-nova-improper-access-control-in-xenapi-backend"},{"cve":"CVE-2013-2096","cvss":4,"epss":0.0039,"slug":"cve-2013-2096-openstack-compute-nova-does-not-verify-the-virtual-size-of-a-qcow2","title":"PYSEC-2026-876 - OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:26.645846+00:00","url":"https://junglewise.ai/threats/cve-2013-2096-openstack-compute-nova-does-not-verify-the-virtual-size-of-a-qcow2"},{"cve":"CVE-2013-6419","cvss":0,"epss":0.0185,"slug":"cve-2013-6419-openstack-nova-metadata-queries-tenant-isolation-bypass","title":"PYSEC-2026-858 - OpenStack Nova Router metadata queries are not restricted by tenant","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.550626+00:00","url":"https://junglewise.ai/threats/cve-2013-6419-openstack-nova-metadata-queries-tenant-isolation-bypass"},{"cve":"CVE-2013-4463","epss":0.0037,"slug":"cve-2013-4463-openstack-nova-denial-of-service-through-compressed-disk-images","title":"PYSEC-2026-865 - OpenStack Nova denial of service through compressed disk images","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.984717+00:00","url":"https://junglewise.ai/threats/cve-2013-4463-openstack-nova-denial-of-service-through-compressed-disk-images"},{"cve":"CVE-2014-0167","cvss":4,"epss":0.0165,"slug":"cve-2014-0167-openstack-compute-nova-allows-remote-authenticated-users-to-gain","title":"PYSEC-2026-878 - OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:25.931683+00:00","url":"https://junglewise.ai/threats/cve-2014-0167-openstack-compute-nova-allows-remote-authenticated-users-to-gain"},{"cve":"CVE-2013-4469","cvss":0,"epss":0.0044,"slug":"cve-2013-4469-openstack-nova-denial-of-service-in-qcow2-image-validation","title":"PYSEC-2026-860 - OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:25.880153+00:00","url":"https://junglewise.ai/threats/cve-2013-4469-openstack-nova-denial-of-service-in-qcow2-image-validation"},{"cve":"CVE-2015-5162","cvss":3,"epss":0.0309,"slug":"cve-2015-5162-openstack-cinder-glance-and-nova-contain-uncontrolled-resource","title":"PYSEC-2026-871 - OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.240424+00:00","url":"https://junglewise.ai/threats/cve-2015-5162-openstack-cinder-glance-and-nova-contain-uncontrolled-resource"},{"cve":"CVE-2012-1585","epss":0.0209,"slug":"cve-2012-1585-openstack-nova-long-server-names-grow-nova-api-log-files","title":"PYSEC-2026-880 - OpenStack Nova Long server names grow nova-api log files significantly","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:23.16534+00:00","url":"https://junglewise.ai/threats/cve-2012-1585-openstack-nova-long-server-names-grow-nova-api-log-files"},{"cve":"CVE-2013-4185","epss":0.0211,"slug":"cve-2013-4185-openstack-nova-denial-of-service-in-network-source-security-groups","title":"PYSEC-2026-879 - OpenStack Nova Denial of Service in network source security groups","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:23.117396+00:00","url":"https://junglewise.ai/threats/cve-2013-4185-openstack-nova-denial-of-service-in-network-source-security-groups"},{"cve":"CVE-2014-3517","epss":0.0195,"slug":"cve-2014-3517-openstack-compute-nova-exposure-of-sensitive-information-to-an","title":"PYSEC-2026-884 - OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:23.061204+00:00","url":"https://junglewise.ai/threats/cve-2014-3517-openstack-compute-nova-exposure-of-sensitive-information-to-an"},{"cve":"CVE-2011-4596","epss":0.0176,"slug":"cve-2011-4596-openstack-nova-multiple-directory-traversal-vulnerabilities","title":"PYSEC-2026-881 - OpenStack Nova Multiple directory traversal vulnerabilities","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:23.012308+00:00","url":"https://junglewise.ai/threats/cve-2011-4596-openstack-nova-multiple-directory-traversal-vulnerabilities"},{"cve":"CVE-2013-2256","epss":0.0184,"slug":"cve-2013-2256-openstack-compute-nova-allows-remote-authenticated-users-to-obtain","title":"PYSEC-2026-866 - OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.803223+00:00","url":"https://junglewise.ai/threats/cve-2013-2256-openstack-compute-nova-allows-remote-authenticated-users-to-obtain"},{"cve":"CVE-2015-8749","cvss":3,"epss":0.0224,"slug":"cve-2015-8749-openstack-nova-potential-xen-connection-password-leak-via","title":"PYSEC-2026-870 - OpenStack Nova Potential Xen connection password leak via StorageError","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:22.625114+00:00","url":"https://junglewise.ai/threats/cve-2015-8749-openstack-nova-potential-xen-connection-password-leak-via"},{"cve":"CVE-2013-6437","epss":0.0204,"slug":"cve-2013-6437-openstack-nova-dos-through-ephemeral-disk-backing-files","title":"PYSEC-2026-874 - OpenStack Nova DoS through ephemeral disk backing files","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.569278+00:00","url":"https://junglewise.ai/threats/cve-2013-6437-openstack-nova-dos-through-ephemeral-disk-backing-files"},{"cve":"CVE-2015-3241","epss":0.0348,"slug":"cve-2015-3241-openstack-nova-instance-migration-process-does-not-stop-when","title":"PYSEC-2026-861 - OpenStack Nova instance migration process does not stop when instance is deleted","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.520788+00:00","url":"https://junglewise.ai/threats/cve-2015-3241-openstack-nova-instance-migration-process-does-not-stop-when"},{"cve":"CVE-2015-7713","epss":0.037,"slug":"cve-2015-7713-openstack-compute-nova-allows-remote-attackers-to-bypass-intended","title":"PYSEC-2026-867 - OpenStack Compute (Nova) allows remote attackers to bypass intended restriction","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.46914+00:00","url":"https://junglewise.ai/threats/cve-2015-7713-openstack-compute-nova-allows-remote-attackers-to-bypass-intended"},{"cve":"CVE-2014-3708","epss":0.0281,"slug":"cve-2014-3708-openstack-compute-nova-denial-of-service-vulnerability","title":"PYSEC-2026-863 - OpenStack Compute (Nova) Denial of Service vulnerability","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.414704+00:00","url":"https://junglewise.ai/threats/cve-2014-3708-openstack-compute-nova-denial-of-service-vulnerability"},{"cve":"CVE-2014-3608","epss":0.0173,"slug":"cve-2014-3608-openstack-compute-nova-s-vmware-driver-vulnerable-to-denial-of","title":"PYSEC-2026-869 - OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:22.364305+00:00","url":"https://junglewise.ai/threats/cve-2014-3608-openstack-compute-nova-s-vmware-driver-vulnerable-to-denial-of"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":29},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"nova (PyPI)","slug":"pypi-nova","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"OpenStack compute service for managing virtual machine instances and cloud resources.","url":"https://junglewise.ai/threats/technologies/pypi-nova"},"most_severe":[{"cve":"CVE-2026-24708","cvss":8.2,"epss":0.0038,"slug":"cve-2026-24708-openstack-nova-host-data-destruction-via-unsafe-qemu-img-resize","title":"OpenStack Nova host data destruction via unsafe qemu-img resize","severity":"high","exploited":false,"published_at":"2026-02-18T18:24:33.087+00:00","url":"https://junglewise.ai/threats/cve-2026-24708-openstack-nova-host-data-destruction-via-unsafe-qemu-img-resize"},{"cve":"CVE-2026-46448","cvss":5.4,"epss":0.0046,"slug":"cve-2026-46448-openstack-nova-scheduler-hint-injection-in-server-create-api","title":"OpenStack Nova scheduler hint injection in server create API","severity":"medium","exploited":false,"published_at":"2026-06-16T20:16:41.697+00:00","url":"https://junglewise.ai/threats/cve-2026-46448-openstack-nova-scheduler-hint-injection-in-server-create-api"},{"cve":"CVE-2012-5625","cvss":4.3,"epss":0.0201,"slug":"cve-2012-5625-openstack-nova-information-leak-in-libvirt-lvm-backed-instances","title":"OpenStack Nova information leak in libvirt LVM-backed instances","severity":"medium","exploited":false,"published_at":"2022-05-17T05:15:11+00:00","url":"https://junglewise.ai/threats/cve-2012-5625-openstack-nova-information-leak-in-libvirt-lvm-backed-instances"},{"cve":"CVE-2014-0167","cvss":4,"epss":0.0165,"slug":"cve-2014-0167-openstack-compute-nova-allows-remote-authenticated-users-to-gain","title":"PYSEC-2026-878 - OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:25.931683+00:00","url":"https://junglewise.ai/threats/cve-2014-0167-openstack-compute-nova-allows-remote-authenticated-users-to-gain"},{"cve":"CVE-2013-2096","cvss":4,"epss":0.0039,"slug":"cve-2013-2096-openstack-compute-nova-does-not-verify-the-virtual-size-of-a-qcow2","title":"PYSEC-2026-876 - OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:26.645846+00:00","url":"https://junglewise.ai/threats/cve-2013-2096-openstack-compute-nova-does-not-verify-the-virtual-size-of-a-qcow2"},{"cve":"CVE-2021-3654","cvss":3.1,"epss":0.2679,"slug":"cve-2021-3654-open-redirect-in-cpython-that-affects-users-of-openstack-nova","title":"PYSEC-2026-693 - Open Redirect in CPython that affects users of OpenStack Nova","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:15.447305+00:00","url":"https://junglewise.ai/threats/cve-2021-3654-open-redirect-in-cpython-that-affects-users-of-openstack-nova"},{"cve":"CVE-2013-1838","cvss":3.1,"epss":0.0274,"slug":"cve-2013-1838-openstack-compute-nova-denial-of-service-via-a-large-number-of","title":"PYSEC-2013-44 - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote","severity":"low","exploited":false,"published_at":"2013-03-22T21:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-1838-openstack-compute-nova-denial-of-service-via-a-large-number-of"},{"cve":"CVE-2013-7130","cvss":3.1,"epss":0.0244,"slug":"cve-2013-7130-openstack-nova-live-migration-can-leak-root-disk-into-ephemeral","title":"PYSEC-2014-111 - The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Ic","severity":"low","exploited":false,"published_at":"2014-02-06T17:00:00+00:00","url":"https://junglewise.ai/threats/cve-2013-7130-openstack-nova-live-migration-can-leak-root-disk-into-ephemeral"},{"cve":"CVE-2013-0335","cvss":3.1,"epss":0.0214,"slug":"cve-2013-0335-openstack-compute-nova-unauthorised-access-to-arbitrary-vm-using","title":"PYSEC-2013-43 - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunis","severity":"low","exploited":false,"published_at":"2013-03-22T21:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-0335-openstack-compute-nova-unauthorised-access-to-arbitrary-vm-using"},{"cve":"CVE-2019-14433","cvss":3.1,"epss":0.0194,"slug":"cve-2019-14433-openstack-nova-server-resource-faults-leak-external-exception","title":"PYSEC-2019-191 - An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticate","severity":"low","exploited":false,"published_at":"2019-08-09T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-14433-openstack-nova-server-resource-faults-leak-external-exception"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}