---
id: CVE-2013-4185
aliases:
  - GHSA-ph2h-hh49-vh27
  - PYSEC-2026-879
title: OpenStack Nova Denial of Service in network source security groups
summary: OpenStack Nova Denial of Service in network source security groups
severity: medium
vendor: nova
product: nova
ecosystem: pip
affected:
  - nova < 12.0.0a0
patched:
  - nova 12.0.0a0
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-ph2h-hh49-vh27'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-4185'
  - url: 'https://bugs.launchpad.net/nova/+bug/1184041'
  - url: 'https://github.com/openstack/nova'
  - url: >-
      http://github.com/openstack/nova/commit/52ad911963da4095b213952dee3a430fe0c4c30f
  - url: >-
      http://github.com/openstack/nova/commit/85aac04704350566d6b06aa7a3b99649946c672c
  - url: >-
      http://github.com/openstack/nova/commit/d4ee081c5c0a5132781235177c430ebcf72b0b0b
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-1199.html'
  - url: 'http://seclists.org/oss-sec/2013/q3/282'
tags:
  - osv
  - pip
epss: 0.02105
epssPercentile: 0.80659
ingestedAt: '2026-07-08T18:25:51.773Z'
---

## Overview

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.

## Affected packages

- `nova < 12.0.0a0`

## Remediation

Upgrade to a patched release:

- `nova 12.0.0a0`
