---
id: CVE-2014-7960
aliases:
  - GHSA-g6x3-55qv-x6p2
  - PYSEC-2026-933
title: OpenStack Swift metadata constraints are not correctly enforced
summary: OpenStack Swift metadata constraints are not correctly enforced
severity: medium
vendor: swift
product: swift
ecosystem: pip
affected:
  - swift < 2.2.0
patched:
  - swift 2.2.0
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-g6x3-55qv-x6p2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2014-7960'
  - url: >-
      https://github.com/openstack/swift/commit/06800cbe446ce4c937a57b69517b55c3bba9b6e1
  - url: >-
      https://github.com/openstack/swift/commit/2c4622a28ea04e1c6b2382189b0a1f6cccdc9c0f
  - url: >-
      https://github.com/openstack/swift/commit/5b2c27a5874c2b5b0a333e4955b03544f6a8119f
  - url: 'https://bugs.launchpad.net/swift/+bug/1365350'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/96901'
  - url: 'https://github.com/openstack/swift'
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-0835.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-0836.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1495.html'
  - url: 'http://www.openwall.com/lists/oss-security/2014/10/07/39'
  - url: 'http://www.openwall.com/lists/oss-security/2014/10/08/7'
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
  - url: 'http://www.securityfocus.com/bid/70279'
  - url: 'http://www.ubuntu.com/usn/USN-2704-1'
tags:
  - osv
  - pip
epss: 0.03049
epssPercentile: 0.86917
ingestedAt: '2026-07-08T18:25:49.652Z'
---

## Overview

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

## Affected packages

- `swift < 2.2.0`

## Remediation

Upgrade to a patched release:

- `swift 2.2.0`
