{"schema_version":1,"title":"OpenStack vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in OpenStack: 6 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-51773, was published on 25 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/openstack","json_url":"https://junglewise.ai/threats/vendors/openstack.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openstack","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":7,"all_time":43,"critical":2,"exploited":0,"last_7_days":6,"last_30_days":9,"last_90_days":20,"last_365_days":40},"latest":[{"cve":"CVE-2026-51773","cvss":8.1,"slug":"cve-2026-51773-an-issue-in-the-vmware-datastore-driver-of-openstack-glance-store","title":"OpenStack glance_store credential leak in VMware datastore driver","severity":"high","exploited":false,"published_at":"2026-09-25T13:17:14.673+00:00","url":"https://junglewise.ai/threats/cve-2026-51773-an-issue-in-the-vmware-datastore-driver-of-openstack-glance-store"},{"cve":"CVE-2026-51772","slug":"cve-2026-51772-a-server-side-request-forgery-ssrf-vulnerability-exists-in-the","title":"OpenStack Glance Image API server-side request forgery","severity":"info","exploited":false,"published_at":"2026-09-25T13:17:14.55+00:00","url":"https://junglewise.ai/threats/cve-2026-51772-a-server-side-request-forgery-ssrf-vulnerability-exists-in-the"},{"cve":"CVE-2026-97404","epss":0.0027,"slug":"cve-2026-97404-in-openstack-zaqar-before-22-0-2-wsgi-transport-mishandles-the","title":"OpenStack Zaqar authentication bypass in WSGI transport","severity":"info","exploited":false,"published_at":"2026-09-24T15:18:01.537+00:00","url":"https://junglewise.ai/threats/cve-2026-97404-in-openstack-zaqar-before-22-0-2-wsgi-transport-mishandles-the"},{"cve":"CVE-2026-97149","epss":0.0024,"slug":"cve-2026-97149-in-openstack-swift-before-2-38-2-the-tempurl-middleware-does-not","title":"OpenStack Swift tempurl information disclosure via X-Copy-From","severity":"info","exploited":false,"published_at":"2026-09-24T03:16:59.133+00:00","url":"https://junglewise.ai/threats/cve-2026-97149-in-openstack-swift-before-2-38-2-the-tempurl-middleware-does-not"},{"cve":"CVE-2026-94572","epss":0.0053,"slug":"cve-2026-94572-in-openstack-octavia-before-18-0-1-the-amphora-provider-driver","title":"OpenStack Octavia HAProxy configuration injection in tls_ciphers field","severity":"info","exploited":false,"published_at":"2026-09-21T21:17:22.15+00:00","url":"https://junglewise.ai/threats/cve-2026-94572-in-openstack-octavia-before-18-0-1-the-amphora-provider-driver"},{"cve":"CVE-2026-94571","epss":0.0053,"slug":"cve-2026-94571-in-openstack-octavia-before-18-0-1-the-amphora-provider-driver","title":"OpenStack Octavia HAProxy configuration injection via L7 redirect URL","severity":"info","exploited":false,"published_at":"2026-09-21T21:17:21.97+00:00","url":"https://junglewise.ai/threats/cve-2026-94571-in-openstack-octavia-before-18-0-1-the-amphora-provider-driver"},{"cve":"CVE-2026-93854","epss":0.0041,"slug":"cve-2026-93854-in-openstack-blazar-before-17-0-1-the-v2-lease-api-does-not","title":"OpenStack Blazar authorization bypass in Lease API","severity":"info","exploited":false,"published_at":"2026-09-18T19:17:25.44+00:00","url":"https://junglewise.ai/threats/cve-2026-93854-in-openstack-blazar-before-17-0-1-the-v2-lease-api-does-not"},{"cve":"CVE-2026-93852","epss":0.0037,"slug":"cve-2026-93852-in-openstack-blazar-before-17-0-1-the-v2-lease-listing-operation","title":"OpenStack Blazar authorization bypass in Lease API","severity":"info","exploited":false,"published_at":"2026-09-18T19:17:25.267+00:00","url":"https://junglewise.ai/threats/cve-2026-93852-in-openstack-blazar-before-17-0-1-the-v2-lease-listing-operation"},{"cve":"CVE-2026-90461","cvss":6.3,"epss":0.0033,"slug":"cve-2026-90461-openstack-ironic-credential-leakage-in-http-basic-authentication","title":"OpenStack Ironic credential leakage in HTTP Basic Authentication","severity":"medium","exploited":false,"published_at":"2026-09-11T22:16:48.403+00:00","url":"https://junglewise.ai/threats/cve-2026-90461-openstack-ironic-credential-leakage-in-http-basic-authentication"},{"cve":"CVE-2026-76878","epss":0.0054,"slug":"cve-2026-76878-openstack-aodh-project-scoping-bypass-in-alarm-list-api","title":"OpenStack Aodh project scoping bypass in alarm list API","severity":"info","exploited":false,"published_at":"2026-08-19T22:17:28.31+00:00","url":"https://junglewise.ai/threats/cve-2026-76878-openstack-aodh-project-scoping-bypass-in-alarm-list-api"},{"cve":"CVE-2026-74250","cvss":6.3,"epss":0.003,"slug":"cve-2026-74250-openstack-ironic-autodetect-deploy-interface-cleaning-bypass","title":"OpenStack Ironic autodetect deploy interface cleaning bypass","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.853+00:00","url":"https://junglewise.ai/threats/cve-2026-74250-openstack-ironic-autodetect-deploy-interface-cleaning-bypass"},{"cve":"CVE-2026-74248","cvss":4.3,"epss":0.0033,"slug":"cve-2026-74248-openstack-octavia-qos-policy-authorization-bypass","title":"OpenStack Octavia QoS policy authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-14T21:17:58.173+00:00","url":"https://junglewise.ai/threats/cve-2026-74248-openstack-octavia-qos-policy-authorization-bypass"},{"cve":"CVE-2026-55707","cvss":6.5,"epss":0.0043,"slug":"cve-2026-55707-openstack-neutron-subnetpool-onboarding-authorization-bypass","title":"OpenStack Neutron subnetpool onboarding authorization bypass","severity":"info","exploited":false,"published_at":"2026-08-05T06:16:37.903+00:00","url":"https://junglewise.ai/threats/cve-2026-55707-openstack-neutron-subnetpool-onboarding-authorization-bypass"},{"cve":"CVE-2026-66139","cvss":4.8,"slug":"cve-2026-66139-openstack-zaqar-authentication-bypass-via-extra-spec-header","title":"OpenStack Zaqar authentication bypass via EXTRA-SPEC header","severity":"medium","exploited":false,"published_at":"2026-07-24T05:16:49.577+00:00","url":"https://junglewise.ai/threats/cve-2026-66139-openstack-zaqar-authentication-bypass-via-extra-spec-header"},{"cve":"CVE-2026-54423","cvss":8.2,"slug":"cve-2026-54423-openstack-ironic-rbac-bypass-in-ipmi-raw-command-execution","title":"OpenStack Ironic RBAC bypass in IPMI raw command execution","severity":"high","exploited":false,"published_at":"2026-07-10T04:17:52.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54423-openstack-ironic-rbac-bypass-in-ipmi-raw-command-execution"},{"cve":"CVE-2026-44918","cvss":5.5,"slug":"cve-2026-44918-openstack-ironic-missing-authorization-in-cross-project-node","title":"OpenStack Ironic missing authorization in cross-project node operations","severity":"medium","exploited":false,"published_at":"2026-07-10T04:17:51.53+00:00","url":"https://junglewise.ai/threats/cve-2026-44918-openstack-ironic-missing-authorization-in-cross-project-node"},{"cve":"CVE-2024-7319","cvss":3.1,"epss":0.0039,"slug":"cve-2024-7319-openstack-heat-sensitive-information-disclosure-in-stack-abandon","title":"PYSEC-2026-1750 - openstack-heat may disclose sensitive information","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.273529+00:00","url":"https://junglewise.ai/threats/cve-2024-7319-openstack-heat-sensitive-information-disclosure-in-stack-abandon"},{"cve":"CVE-2022-47950","cvss":3.1,"epss":0.0101,"slug":"cve-2022-47950-openstack-swift-xxe-injection-in-s3-api","title":"PYSEC-2026-927 - OpenStack Swift XML external entities (XXE) Injection","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:27.00112+00:00","url":"https://junglewise.ai/threats/cve-2022-47950-openstack-swift-xxe-injection-in-s3-api"},{"cve":"CVE-2013-4497","epss":0.0182,"slug":"cve-2013-4497-openstack-compute-nova-improper-access-control-in-xenapi-backend","title":"PYSEC-2026-859 - OpenStack Compute Nova Improper Access Control","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.876718+00:00","url":"https://junglewise.ai/threats/cve-2013-4497-openstack-compute-nova-improper-access-control-in-xenapi-backend"},{"cve":"CVE-2013-6419","cvss":0,"epss":0.0185,"slug":"cve-2013-6419-openstack-nova-metadata-queries-tenant-isolation-bypass","title":"PYSEC-2026-858 - OpenStack Nova Router metadata queries are not restricted by tenant","severity":"info","exploited":false,"published_at":"2026-07-06T08:03:26.550626+00:00","url":"https://junglewise.ai/threats/cve-2013-6419-openstack-nova-metadata-queries-tenant-isolation-bypass"},{"cve":"CVE-2026-50221","cvss":5.4,"epss":0.0022,"slug":"cve-2026-50221-openstack-swift-ssrf-via-header-injection-in-proxy-server","title":"OpenStack Swift SSRF via header injection in proxy-server","severity":"medium","exploited":false,"published_at":"2026-06-23T18:18:04.44+00:00","url":"https://junglewise.ai/threats/cve-2026-50221-openstack-swift-ssrf-via-header-injection-in-proxy-server"},{"cve":"CVE-2026-54421","cvss":6.8,"epss":0.0047,"slug":"cve-2026-54421-openstack-ironic-sensitive-information-disclosure-in-volume","title":"OpenStack Ironic sensitive information disclosure in volume target PATCH response","severity":"medium","exploited":false,"published_at":"2026-06-14T04:16:30.927+00:00","url":"https://junglewise.ai/threats/cve-2026-54421-openstack-ironic-sensitive-information-disclosure-in-volume"},{"cve":"CVE-2026-50589","cvss":5.3,"epss":0.0074,"slug":"cve-2026-50589-openstack-ironic-denial-of-service-via-crafted-json-in-api","title":"OpenStack Ironic denial of service via crafted JSON in API endpoints","severity":"medium","exploited":false,"published_at":"2026-06-05T00:17:09.213+00:00","url":"https://junglewise.ai/threats/cve-2026-50589-openstack-ironic-denial-of-service-via-crafted-json-in-api"},{"cve":"CVE-2026-50266","cvss":3.1,"epss":0.0038,"slug":"cve-2026-50266-openstack-neutron-rbac-policy-bypass-in-shared-network-ports","title":"OpenStack Neutron RBAC policy bypass in shared network ports","severity":"low","exploited":false,"published_at":"2026-06-04T17:16:33.517+00:00","url":"https://junglewise.ai/threats/cve-2026-50266-openstack-neutron-rbac-policy-bypass-in-shared-network-ports"},{"cve":"CVE-2026-44393","cvss":7.4,"epss":0.0028,"slug":"cve-2026-44393-openstack-oslo-messaging-tls-hostname-verification-failure-in","title":"OpenStack oslo.messaging TLS hostname verification failure in RabbitMQ driver","severity":"high","exploited":false,"published_at":"2026-06-04T16:16:38.497+00:00","url":"https://junglewise.ai/threats/cve-2026-44393-openstack-oslo-messaging-tls-hostname-verification-failure-in"}],"vendor":{"hub":true,"name":"OpenStack","slug":"openstack","homepage":"https://www.openstack.org/","description":"Open-source cloud computing platform for building and managing public and private clouds.","url":"https://junglewise.ai/threats/vendors/openstack"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"most_severe":[{"cve":"CVE-2026-41283","cvss":9.9,"epss":0.0092,"slug":"cve-2026-41283-openstack-mistral-remote-code-execution-via-policy-bypass","title":"OpenStack Mistral remote code execution via policy bypass","severity":"critical","exploited":false,"published_at":"2026-06-04T04:17:12.7+00:00","url":"https://junglewise.ai/threats/cve-2026-41283-openstack-mistral-remote-code-execution-via-policy-bypass"},{"cve":"CVE-2026-22797","cvss":9.9,"epss":0.0045,"slug":"cve-2026-22797-openstack-keystonemiddleware-privilege-escalation-via-identity","title":"OpenStack keystonemiddleware privilege escalation via identity header spoofing","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:04.95+00:00","url":"https://junglewise.ai/threats/cve-2026-22797-openstack-keystonemiddleware-privilege-escalation-via-identity"},{"cve":"CVE-2026-54423","cvss":8.2,"slug":"cve-2026-54423-openstack-ironic-rbac-bypass-in-ipmi-raw-command-execution","title":"OpenStack Ironic RBAC bypass in IPMI raw command execution","severity":"high","exploited":false,"published_at":"2026-07-10T04:17:52.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54423-openstack-ironic-rbac-bypass-in-ipmi-raw-command-execution"},{"cve":"CVE-2026-51773","cvss":8.1,"slug":"cve-2026-51773-an-issue-in-the-vmware-datastore-driver-of-openstack-glance-store","title":"OpenStack glance_store credential leak in VMware datastore driver","severity":"high","exploited":false,"published_at":"2026-09-25T13:17:14.673+00:00","url":"https://junglewise.ai/threats/cve-2026-51773-an-issue-in-the-vmware-datastore-driver-of-openstack-glance-store"},{"cve":"CVE-2026-43003","cvss":8,"epss":0.0113,"slug":"cve-2026-43003-openstack-ironic-python-agent-command-injection-via-malicious","title":"OpenStack Ironic Python Agent command injection via malicious image","severity":"high","exploited":false,"published_at":"2026-05-01T09:16:17.44+00:00","url":"https://junglewise.ai/threats/cve-2026-43003-openstack-ironic-python-agent-command-injection-via-malicious"},{"cve":"CVE-2026-42997","cvss":7.7,"epss":0.0054,"slug":"cve-2026-42997-openstack-ironic-credential-forwarding-in-idrac-configuration","title":"OpenStack Ironic Credential Forwarding in iDRAC Configuration Molds","severity":"high","exploited":false,"published_at":"2026-05-05T19:16:22.817+00:00","url":"https://junglewise.ai/threats/cve-2026-42997-openstack-ironic-credential-forwarding-in-idrac-configuration"},{"cve":"CVE-2026-40213","cvss":7.4,"epss":0.0033,"slug":"cve-2026-40213-openstack-cyborg-incorrect-authorization-in-multiple-api","title":"OpenStack Cyborg incorrect authorization in multiple API endpoints","severity":"high","exploited":false,"published_at":"2026-05-08T00:31:33+00:00","url":"https://junglewise.ai/threats/cve-2026-40213-openstack-cyborg-incorrect-authorization-in-multiple-api"},{"cve":"CVE-2026-44393","cvss":7.4,"epss":0.0028,"slug":"cve-2026-44393-openstack-oslo-messaging-tls-hostname-verification-failure-in","title":"OpenStack oslo.messaging TLS hostname verification failure in RabbitMQ driver","severity":"high","exploited":false,"published_at":"2026-06-04T16:16:38.497+00:00","url":"https://junglewise.ai/threats/cve-2026-44393-openstack-oslo-messaging-tls-hostname-verification-failure-in"},{"cve":"CVE-2026-49017","cvss":4,"epss":0.0036,"slug":"cve-2026-49017-openstack-swift-infinite-loop-in-s3api-middleware-via-truncated","title":"OpenStack Swift infinite loop in s3api middleware via truncated PUT request","severity":"high","exploited":false,"published_at":"2026-05-27T02:16:34.327+00:00","url":"https://junglewise.ai/threats/cve-2026-49017-openstack-swift-infinite-loop-in-s3api-middleware-via-truncated"},{"cve":"CVE-2026-54421","cvss":6.8,"epss":0.0047,"slug":"cve-2026-54421-openstack-ironic-sensitive-information-disclosure-in-volume","title":"OpenStack Ironic sensitive information disclosure in volume target PATCH response","severity":"medium","exploited":false,"published_at":"2026-06-14T04:16:30.927+00:00","url":"https://junglewise.ai/threats/cve-2026-54421-openstack-ironic-sensitive-information-disclosure-in-volume"}],"generated_at":"2026-09-26T13:07:00.120236+00:00","technologies":[{"name":"OpenStack Ironic","slug":"ironic","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/ironic"},{"name":"OpenStack Neutron","slug":"neutron","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/neutron"},{"name":"OpenStack Swift","slug":"swift","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/swift"}]}