Known Vulnerabilities for Openstack by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Openstack" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71201 json | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71194 json | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY r... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-71193 json | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint)... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-71192 json | In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-F... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-71191 json | In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 s... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-71190 json | In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastro... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-66139 json | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-66138 json | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code exec... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-55748 json | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with ... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-55707 json | In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authent... | Not Provided | 2026-08-05 | 2026-08-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openstack | 7.0 | |||
| Application | Redhat | Openstack | 5.0 | |||
| Application | Redhat | Openstack | 4.0 | |||
| Application | Redhat | Openstack | 3.0 | |||
| Application | Redhat | Openstack | 2.1 | |||
| Application | Redhat | Openstack | 2.0 | |||
| Application | Redhat | Openstack | 16.1 | |||
| Application | Redhat | Openstack | 15.0 | |||
| Application | Redhat | Openstack | 14 | |||
| Application | Redhat | Openstack | 13.0 | |||
| Application | Redhat | Openstack | 12 | |||
| Application | Redhat | Openstack | 11 | |||
| Application | Redhat | Openstack | 10 |