Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-42998Medium· 6.0OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-42999Medium· 6.0OpenStack Keystone has an Authorization Bypass
CVE-2025-65073High· 7.5OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
CVE-2021-38155High· 7.5OpenStack Keystone allows information disclosure during account locking
CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation
CVE-2012-4413MediumOpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2013-4477LowOpenStack Identity Keystone Privilege Escalation vulnerability
CVE-2012-4457MediumOpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2012-4456HighOpenStack Keystone Improper Authentication vulnerability
CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
CVE-2015-3646MediumOpenStack Keystone Logs Passwords
CVE-2014-0204MediumOpenStack Identity Keystone Improper Privilege Management
CVE-2014-3621MediumOpenStack Identity Keystone Exposure of Sensitive Information
CVE-2013-2014MediumOpenStack Identity (Keystone) Denial of Service
CVE-2014-3476MediumOpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
CVE-2013-0282MediumOpenStack Keystone allows context-dependent attackers to bypass access restrictions
CVE-2013-0270Medium· 6.5OpenStack Keystone Denial of Service vulnerability via a large HTTP request
CVE-2017-2673High· 7.2An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…
CVE-2013-1865NoneOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.