{"id":"CVE-2013-4179","aliases":["GHSA-j6xh-q826-55jw","PYSEC-2026-875"],"title":"OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack","summary":"OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack","severity":"medium","vendor":"nova","product":"nova","ecosystem":"pip","affected":["nova < 2013.2"],"patched":["nova 2013.2"],"published":"2022-05-17","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:38.935217369Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-j6xh-q826-55jw","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4179"},{"url":"https://access.redhat.com/errata/RHSA-2013:1199"},{"url":"https://access.redhat.com/security/cve/CVE-2013-4179"},{"url":"https://bugs.launchpad.net/ossa/+bug/1190229"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=989707"},{"url":"https://opendev.org/openstack/nova"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1199.html"},{"url":"http://www.ubuntu.com/usn/USN-2005-1"}],"tags":["osv","pip"],"epss":0.02725,"epssPercentile":0.85347,"ingestedAt":"2026-07-08T18:25:50.602Z","slug":"CVE-2013-4179","body":"## Overview\n\nThe security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.  NOTE: this issue is due to an incomplete fix for CVE-2013-1664.\n\n## Affected packages\n\n- `nova < 2013.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nova 2013.2`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}