---
id: CVE-2013-0270
aliases:
  - GHSA-4ppj-4p4v-jf4p
  - PYSEC-2026-650
title: OpenStack Keystone Denial of Service vulnerability via a large HTTP request
summary: OpenStack Keystone Denial of Service vulnerability via a large HTTP request
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - keystone < 8.0.0a0
patched:
  - keystone 8.0.0a0
published: '2022-05-05'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-4ppj-4p4v-jf4p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-0270'
  - url: >-
      https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8
  - url: >-
      https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdc
  - url: 'https://access.redhat.com/security/cve/CVE-2013-0270'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1099025'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=909012'
  - url: 'https://launchpad.net/keystone/grizzly/2013.1'
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0708.html'
tags:
  - osv
  - pip
epss: 0.03165
epssPercentile: 0.87455
ingestedAt: '2026-07-08T18:25:45.517Z'
---

## Overview

OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.

## Affected packages

- `keystone < 8.0.0a0`

## Remediation

Upgrade to a patched release:

- `keystone 8.0.0a0`
