---
id: CVE-2011-3147
aliases:
  - GHSA-hqfx-4x4w-vmwp
  - PYSEC-2026-690
title: Openstack nova qcow format could expose host filesystem information
summary: Openstack nova qcow format could expose host filesystem information
severity: low
cvss: 2.8
cvssVector: 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'
vendor: nova
product: nova
ecosystem: pip
affected:
  - nova < 12.0.0a0
patched:
  - nova 12.0.0a0
published: '2022-04-22'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-hqfx-4x4w-vmwp'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2011-3147'
  - url: >-
      https://github.com/openstack/nova/commit/ff9d353b2f4fee469e530fbc8dc231a41f6fed84
  - url: 'https://bugs.launchpad.net/nova/+bug/853330'
  - url: 'http://bazaar.launchpad.net/~hudson-openstack/nova/trunk/revision/1604'
tags:
  - osv
  - pip
epss: 0.0074
epssPercentile: 0.52692
ingestedAt: '2026-07-08T18:25:50.308Z'
---

## Overview

Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.

## Affected packages

- `nova < 12.0.0a0`

## Remediation

Upgrade to a patched release:

- `nova 12.0.0a0`
