---
id: CVE-2012-1585
aliases:
  - GHSA-pjvw-p2v5-wf6q
  - PYSEC-2026-880
title: OpenStack Nova Long server names grow nova-api log files significantly
summary: OpenStack Nova Long server names grow nova-api log files significantly
severity: medium
vendor: nova
product: nova
ecosystem: pip
affected:
  - nova < 12.0.0a0
patched:
  - nova 12.0.0a0
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pjvw-p2v5-wf6q'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2012-1585'
  - url: 'https://bugs.launchpad.net/nova/+bug/962515'
  - url: 'https://github.com/openstack/nova'
  - url: >-
      http://github.com/openstack/nova/commit/0fa7d12dbfb7ae016657dd91034b4c0781ea43de
  - url: >-
      http://github.com/openstack/nova/commit/1ebec5726c7a9db0a6f29fad0ef747b0c087f702
  - url: >-
      http://github.com/openstack/nova/commit/c7f526fae6062e9ab51f65474af71d496aa66554
  - url: >-
      http://github.com/openstack/nova/commit/c869a41951b77c6930bf4fb4734f05cd3d6ac4b1
  - url: 'http://lwn.net/Alerts/491298'
  - url: 'http://osdir.com/ml/openstack-cloud-computing/2012-03/msg01133.html'
tags:
  - osv
  - pip
epss: 0.0209
epssPercentile: 0.80527
ingestedAt: '2026-07-08T18:25:51.786Z'
---

## Overview

OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.

## Affected packages

- `nova < 12.0.0a0`

## Remediation

Upgrade to a patched release:

- `nova 12.0.0a0`
