---
id: CVE-2013-2014
aliases:
  - GHSA-7332-36h8-8jh8
  - PYSEC-2026-651
title: OpenStack Identity (Keystone) Denial of Service
summary: OpenStack Identity (Keystone) Denial of Service
severity: medium
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - keystone < 8.0.0a0
patched:
  - keystone 8.0.0a0
published: '2022-05-13'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7332-36h8-8jh8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-2014'
  - url: >-
      https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8
  - url: 'https://bugs.launchpad.net/keystone/+bug/1098177'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1099025'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/84347'
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2013-July/111914.html
  - url: 'http://secunia.com/advisories/53397'
  - url: 'http://www.securityfocus.com/bid/59936'
tags:
  - osv
  - pip
epss: 0.03271
epssPercentile: 0.87865
ingestedAt: '2026-07-08T18:25:46.744Z'
---

## Overview

OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.

## Affected packages

- `keystone < 8.0.0a0`

## Remediation

Upgrade to a patched release:

- `keystone 8.0.0a0`
