{"schema_version":1,"title":"python-keystoneclient (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in python-keystoneclient (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2013-2030, was published on 6 July 2026.","url":"https://junglewise.ai/threats/technologies/python-keystoneclient","json_url":"https://junglewise.ai/threats/technologies/python-keystoneclient.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/python-keystoneclient","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":2},"latest":[{"cve":"CVE-2013-2030","cvss":3.1,"epss":0.0024,"slug":"cve-2013-2030-openstack-nova-uses-insecure-keystone-middleware-tmpdir-by-default","title":"PYSEC-2026-911 - OpenStack Nova uses insecure keystone middleware tmpdir by default","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:26.363613+00:00","url":"https://junglewise.ai/threats/cve-2013-2030-openstack-nova-uses-insecure-keystone-middleware-tmpdir-by-default"},{"cve":"CVE-2013-2255","cvss":3.1,"epss":0.0097,"slug":"cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper","title":"PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate Validation","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.847931+00:00","url":"https://junglewise.ai/threats/cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper"},{"cve":"CVE-2013-2167","cvss":3.1,"epss":0.0197,"slug":"cve-2013-2167-insufficient-verification-of-data-authenticity-in-python","title":"PYSEC-2019-161 - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass","severity":"low","exploited":false,"published_at":"2019-12-10T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2167-insufficient-verification-of-data-authenticity-in-python"},{"cve":"CVE-2013-2166","cvss":3.1,"epss":0.0215,"slug":"cve-2013-2166-inadequate-encryption-strength-in-python-keystoneclient","title":"PYSEC-2019-197 - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass","severity":"low","exploited":false,"published_at":"2019-12-10T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2166-inadequate-encryption-strength-in-python-keystoneclient"},{"cve":"CVE-2015-1852","cvss":3.1,"epss":0.0261,"slug":"cve-2015-1852-openstack-keystonemiddleware-and-python-keystoneclient-vulnerable","title":"PYSEC-2015-30 - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verificat","severity":"low","exploited":false,"published_at":"2015-04-17T17:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1852-openstack-keystonemiddleware-and-python-keystoneclient-vulnerable"},{"cve":"CVE-2014-7144","cvss":3.1,"epss":0.0198,"slug":"cve-2014-7144-openstack-keystonemiddleware-does-not-verify-certificate","title":"PYSEC-2014-71 - OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification whe","severity":"low","exploited":false,"published_at":"2014-10-02T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-7144-openstack-keystonemiddleware-does-not-verify-certificate"},{"cve":"CVE-2014-0105","cvss":3.1,"epss":0.011,"slug":"cve-2014-0105-python-keystoneclient-vulnerable-to-context-confusion-in-keystone","title":"PYSEC-2014-70 - The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly ret","severity":"low","exploited":false,"published_at":"2014-04-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-0105-python-keystoneclient-vulnerable-to-context-confusion-in-keystone"},{"cve":"CVE-2013-2104","cvss":3.1,"epss":0.0208,"slug":"cve-2013-2104-python-keystoneclient-missing-expiration-check-in-pki-token","title":"PYSEC-2014-69 - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remo","severity":"low","exploited":false,"published_at":"2014-01-21T18:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2104-python-keystoneclient-missing-expiration-check-in-pki-token"},{"cve":"CVE-2013-2013","cvss":3.1,"epss":0.0037,"slug":"cve-2013-2013-python-keystoneclient-unsecure-user-password-update","title":"PYSEC-2013-24 - The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows loc","severity":"low","exploited":false,"published_at":"2013-10-01T20:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2013-python-keystoneclient-unsecure-user-password-update"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"python-keystoneclient (PyPI)","slug":"python-keystoneclient","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/python-keystoneclient"},"most_severe":[{"cve":"CVE-2015-1852","cvss":3.1,"epss":0.0261,"slug":"cve-2015-1852-openstack-keystonemiddleware-and-python-keystoneclient-vulnerable","title":"PYSEC-2015-30 - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verificat","severity":"low","exploited":false,"published_at":"2015-04-17T17:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-1852-openstack-keystonemiddleware-and-python-keystoneclient-vulnerable"},{"cve":"CVE-2013-2166","cvss":3.1,"epss":0.0215,"slug":"cve-2013-2166-inadequate-encryption-strength-in-python-keystoneclient","title":"PYSEC-2019-197 - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass","severity":"low","exploited":false,"published_at":"2019-12-10T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2166-inadequate-encryption-strength-in-python-keystoneclient"},{"cve":"CVE-2013-2104","cvss":3.1,"epss":0.0208,"slug":"cve-2013-2104-python-keystoneclient-missing-expiration-check-in-pki-token","title":"PYSEC-2014-69 - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remo","severity":"low","exploited":false,"published_at":"2014-01-21T18:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2104-python-keystoneclient-missing-expiration-check-in-pki-token"},{"cve":"CVE-2014-7144","cvss":3.1,"epss":0.0198,"slug":"cve-2014-7144-openstack-keystonemiddleware-does-not-verify-certificate","title":"PYSEC-2014-71 - OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification whe","severity":"low","exploited":false,"published_at":"2014-10-02T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-7144-openstack-keystonemiddleware-does-not-verify-certificate"},{"cve":"CVE-2013-2167","cvss":3.1,"epss":0.0197,"slug":"cve-2013-2167-insufficient-verification-of-data-authenticity-in-python","title":"PYSEC-2019-161 - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass","severity":"low","exploited":false,"published_at":"2019-12-10T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2167-insufficient-verification-of-data-authenticity-in-python"},{"cve":"CVE-2014-0105","cvss":3.1,"epss":0.011,"slug":"cve-2014-0105-python-keystoneclient-vulnerable-to-context-confusion-in-keystone","title":"PYSEC-2014-70 - The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly ret","severity":"low","exploited":false,"published_at":"2014-04-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-0105-python-keystoneclient-vulnerable-to-context-confusion-in-keystone"},{"cve":"CVE-2013-2255","cvss":3.1,"epss":0.0097,"slug":"cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper","title":"PYSEC-2026-656 - OpenStack Keystone and other components vulnerable to Improper Certificate Validation","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.847931+00:00","url":"https://junglewise.ai/threats/cve-2013-2255-openstack-keystone-and-other-components-vulnerable-to-improper"},{"cve":"CVE-2013-2013","cvss":3.1,"epss":0.0037,"slug":"cve-2013-2013-python-keystoneclient-unsecure-user-password-update","title":"PYSEC-2013-24 - The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows loc","severity":"low","exploited":false,"published_at":"2013-10-01T20:55:00+00:00","url":"https://junglewise.ai/threats/cve-2013-2013-python-keystoneclient-unsecure-user-password-update"},{"cve":"CVE-2013-2030","cvss":3.1,"epss":0.0024,"slug":"cve-2013-2030-openstack-nova-uses-insecure-keystone-middleware-tmpdir-by-default","title":"PYSEC-2026-911 - OpenStack Nova uses insecure keystone middleware tmpdir by default","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:26.363613+00:00","url":"https://junglewise.ai/threats/cve-2013-2030-openstack-nova-uses-insecure-keystone-middleware-tmpdir-by-default"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}