---
id: CVE-2014-0006
aliases:
  - PYSEC-2014-116
  - GHSA-cf9m-q836-vf26
title: >-
  The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through
  1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …
summary: >-
  The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through
  1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain
  secret URLs by leveraging an object name and a timing side-channel attack.
severity: none
vendor: swift
product: swift
ecosystem: pip
affected:
  - 'swift >= 1.4.6, < 1.12.0'
patched:
  - swift 1.12.0
published: '2014-01-23'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2014-116'
references:
  - url: 'https://bugs.launchpad.net/swift/+bug/1265665'
  - url: 'http://www.openwall.com/lists/oss-security/2014/01/17/5'
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0232.html'
tags:
  - osv
  - pip
epss: 0.01911
epssPercentile: 0.78925
ingestedAt: '2026-07-13T18:58:05.627Z'
---

## Overview

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

## Affected packages

- `swift >= 1.4.6, < 1.12.0`

## Remediation

Upgrade to a patched release:

- `swift 1.12.0`
