{"id":"CVE-2016-0738","aliases":["GHSA-fxwr-2vxm-cg7p","PYSEC-2026-932"],"title":"OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service","summary":"OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"swift","product":"swift","ecosystem":"pip","affected":["swift < 2.3.1","swift >= 2.4.0, < 2.5.1"],"patched":["swift 2.3.1","swift 2.5.1"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-fxwr-2vxm-cg7p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0738"},{"url":"https://web.archive.org/web/20200228001102/http://www.securityfocus.com/bid/81432"},{"url":"https://security.openstack.org/ossa/OSSA-2016-004.html"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-0329.html"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-0155.html"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-0128.html"},{"url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.html"},{"url":"https://github.com/openstack/swift/blob/master/CHANGELOG"},{"url":"https://github.com/openstack/swift"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1298905"},{"url":"https://bugs.launchpad.net/cloud-archive/+bug/1493303"},{"url":"https://access.redhat.com/security/cve/CVE-2016-0738"},{"url":"https://access.redhat.com/errata/RHSA-2016:0329"},{"url":"https://access.redhat.com/errata/RHSA-2016:0328"},{"url":"https://access.redhat.com/errata/RHSA-2016:0155"},{"url":"https://access.redhat.com/errata/RHSA-2016:0128"},{"url":"https://access.redhat.com/errata/RHSA-2016:0127"},{"url":"https://access.redhat.com/errata/RHSA-2016:0126"}],"tags":["osv","pip"],"epss":0.03787,"epssPercentile":0.89533,"ingestedAt":"2026-07-08T18:25:49.170Z","slug":"CVE-2016-0738","body":"## Overview\n\nOpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.\n\n## Affected packages\n\n- `swift < 2.3.1`\n- `swift >= 2.4.0, < 2.5.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift 2.3.1`\n- `swift 2.5.1`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}