Openstack

    Dashboard / Vendors

    Products: 75
    Vulnerabilities: 319
    Known Exploited: 0
    18
    Critical Level Threats
    63
    High Level Threats
    190
    Medium Level Threats
    44
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-71198

    openstack-glance: openstack-glance: SSRF via location API missing host validation

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-71197

    openstack-glance: openstack-glance: SSRF blocklist bypass via hostname-to-IP resolution gap in web-download

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-71196

    openstack-glance: openstack-glance: SSRF via web-download import due to empty default host filters

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-80183

    In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.

    Last Modified: Aug 27, 2026
    Published: Aug 26, 2026

    CVE-2026-80182

    keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints

    Last Modified: Aug 26, 2026
    Published: Aug 25, 2026
    Items Per Page