{"id":"CVE-2014-7960","aliases":["GHSA-g6x3-55qv-x6p2","PYSEC-2026-933"],"title":"OpenStack Swift metadata constraints are not correctly enforced","summary":"OpenStack Swift metadata constraints are not correctly enforced","severity":"medium","vendor":"swift","product":"swift","ecosystem":"pip","affected":["swift < 2.2.0"],"patched":["swift 2.2.0"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g6x3-55qv-x6p2","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7960"},{"url":"https://github.com/openstack/swift/commit/06800cbe446ce4c937a57b69517b55c3bba9b6e1"},{"url":"https://github.com/openstack/swift/commit/2c4622a28ea04e1c6b2382189b0a1f6cccdc9c0f"},{"url":"https://github.com/openstack/swift/commit/5b2c27a5874c2b5b0a333e4955b03544f6a8119f"},{"url":"https://bugs.launchpad.net/swift/+bug/1365350"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96901"},{"url":"https://github.com/openstack/swift"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0835.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0836.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1495.html"},{"url":"http://www.openwall.com/lists/oss-security/2014/10/07/39"},{"url":"http://www.openwall.com/lists/oss-security/2014/10/08/7"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html"},{"url":"http://www.securityfocus.com/bid/70279"},{"url":"http://www.ubuntu.com/usn/USN-2704-1"}],"tags":["osv","pip"],"epss":0.03049,"epssPercentile":0.86917,"ingestedAt":"2026-07-08T18:25:49.652Z","slug":"CVE-2014-7960","body":"## Overview\n\nOpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.\n\n## Affected packages\n\n- `swift < 2.2.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift 2.2.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}