Known Vulnerabilities for Keystone by OpenStack
Listed below are 10 of the newest known vulnerabilities associated with "Keystone" by "OpenStack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90460 json | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 creden... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-80184 json | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, applicati... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-80183 json | In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped ... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-80182 json | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authent... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-63421 json | Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/quer... | Not Provided | 2026-08-21 | 2026-08-26 |
| CVE-2026-44394 json | Not Provided | 2026-05-28 | 2026-06-02 | |
| CVE-2026-43001 json | An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied p... | Not Provided | 2026-05-01 | 2026-08-14 |
| CVE-2026-43000 json | An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulne... | Not Provided | 2026-05-28 | 2026-07-23 |
| CVE-2026-42999 json | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionall... | Not Provided | 2026-05-28 | 2026-07-23 |
| CVE-2026-42998 json | Not Provided | 2026-05-28 | 2026-06-02 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Keystone | juno-3 | |||
| Application | Openstack | Keystone | juno-2 | |||
| Application | Openstack | Keystone | juno-1 | |||
| Application | Openstack | Keystone | 9.3.0 | |||
| Application | Openstack | Keystone | 9.2.0 | |||
| Application | Openstack | Keystone | 9.1.0 | |||
| Application | Openstack | Keystone | 9.0.2 | |||
| Application | Openstack | Keystone | 9.0.1 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 9.0.0 | |||
| Application | Openstack | Keystone | 8.1.2 | |||
| Application | Openstack | Keystone | 8.1.0 | |||
| Application | Openstack | Keystone | 8.0.2 | |||
| Application | Openstack | Keystone | 8.0.1 | |||
| Application | Openstack | Keystone | 8.0.0 |