{"id":"CVE-2013-4155","aliases":["GHSA-wxx2-gqvv-34hx","PYSEC-2026-935"],"title":"OpenStack Swift allows authenticated users to cause a denial of service","summary":"OpenStack Swift allows authenticated users to cause a denial of service","severity":"medium","vendor":"swift","product":"swift","ecosystem":"pip","affected":["swift < 1.9.1"],"patched":["swift 1.9.1"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wxx2-gqvv-34hx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4155"},{"url":"https://github.com/openstack/swift/commit/1f4ec235cdfd8c868f2d6458532f9dc32c00b8ca"},{"url":"https://github.com/openstack/swift/commit/6b9806e0e8cbec60c0a3ece0bd516e0502827515"},{"url":"https://bugs.launchpad.net/swift/+bug/1196932"},{"url":"https://github.com/openstack/swift"},{"url":"https://review.openstack.org/#/c/40643"},{"url":"https://review.openstack.org/#/c/40645"},{"url":"https://review.openstack.org/#/c/40646"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1197.html"},{"url":"http://www.debian.org/security/2012/dsa-2737"},{"url":"http://www.openwall.com/lists/oss-security/2013/08/07/6"},{"url":"http://www.ubuntu.com/usn/USN-2001-1"}],"tags":["osv","pip"],"epss":0.01675,"epssPercentile":0.75455,"ingestedAt":"2026-07-08T18:25:53.942Z","slug":"CVE-2013-4155","body":"## Overview\n\nOpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service (\"superfluous\" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.\n\n## Affected packages\n\n- `swift < 1.9.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift 1.9.1`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}