---
id: CVE-2016-0737
aliases:
  - GHSA-972c-cfv8-2hq8
  - PYSEC-2026-929
title: >-
  OpenStack Object Storage (Swift) allows remote attackers to cause a denial of
  service
summary: >-
  OpenStack Object Storage (Swift) allows remote attackers to cause a denial of
  service
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: swift
product: swift
ecosystem: pip
affected:
  - swift < 2.4.0
patched:
  - swift 2.4.0
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-972c-cfv8-2hq8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2016-0737'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0126'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0127'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0128'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0155'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0328'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0329'
  - url: 'https://access.redhat.com/security/cve/CVE-2016-0737'
  - url: 'https://bugs.launchpad.net/swift/+bug/1466549'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1298924'
  - url: 'https://launchpad.net/swift/+milestone/2.4.0'
  - url: 'https://opendev.org/openstack/swift'
  - url: 'https://review.openstack.org/#/c/217750'
  - url: 'https://security.openstack.org/ossa/OSSA-2016-004.html'
  - url: >-
      https://web.archive.org/web/20200228001102/http://www.securityfocus.com/bid/81432
tags:
  - osv
  - pip
epss: 0.03754
epssPercentile: 0.89421
ingestedAt: '2026-07-08T18:25:47.773Z'
---

## Overview

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

## Affected packages

- `swift < 2.4.0`

## Remediation

Upgrade to a patched release:

- `swift 2.4.0`
