{"id":"CVE-2013-4185","aliases":["GHSA-ph2h-hh49-vh27","PYSEC-2026-879"],"title":"OpenStack Nova Denial of Service in network source security groups","summary":"OpenStack Nova Denial of Service in network source security groups","severity":"medium","vendor":"nova","product":"nova","ecosystem":"pip","affected":["nova < 12.0.0a0"],"patched":["nova 12.0.0a0"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-ph2h-hh49-vh27","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4185"},{"url":"https://bugs.launchpad.net/nova/+bug/1184041"},{"url":"https://github.com/openstack/nova"},{"url":"http://github.com/openstack/nova/commit/52ad911963da4095b213952dee3a430fe0c4c30f"},{"url":"http://github.com/openstack/nova/commit/85aac04704350566d6b06aa7a3b99649946c672c"},{"url":"http://github.com/openstack/nova/commit/d4ee081c5c0a5132781235177c430ebcf72b0b0b"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1199.html"},{"url":"http://seclists.org/oss-sec/2013/q3/282"}],"tags":["osv","pip"],"epss":0.02105,"epssPercentile":0.80659,"ingestedAt":"2026-07-08T18:25:51.773Z","slug":"CVE-2013-4185","body":"## Overview\n\nAlgorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.\n\n## Affected packages\n\n- `nova < 12.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nova 12.0.0a0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}