---
id: CVE-2016-0738
aliases:
  - GHSA-fxwr-2vxm-cg7p
  - PYSEC-2026-932
title: >-
  OpenStack Object Storage (Swift) allows remote attackers to cause a denial of
  service
summary: >-
  OpenStack Object Storage (Swift) allows remote attackers to cause a denial of
  service
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: swift
product: swift
ecosystem: pip
affected:
  - swift < 2.3.1
  - 'swift >= 2.4.0, < 2.5.1'
patched:
  - swift 2.3.1
  - swift 2.5.1
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-fxwr-2vxm-cg7p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2016-0738'
  - url: >-
      https://web.archive.org/web/20200228001102/http://www.securityfocus.com/bid/81432
  - url: 'https://security.openstack.org/ossa/OSSA-2016-004.html'
  - url: 'https://rhn.redhat.com/errata/RHSA-2016-0329.html'
  - url: 'https://rhn.redhat.com/errata/RHSA-2016-0155.html'
  - url: 'https://rhn.redhat.com/errata/RHSA-2016-0128.html'
  - url: >-
      https://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.html
  - url: 'https://github.com/openstack/swift/blob/master/CHANGELOG'
  - url: 'https://github.com/openstack/swift'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1298905'
  - url: 'https://bugs.launchpad.net/cloud-archive/+bug/1493303'
  - url: 'https://access.redhat.com/security/cve/CVE-2016-0738'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0329'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0328'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0155'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0128'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0127'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0126'
tags:
  - osv
  - pip
epss: 0.03787
epssPercentile: 0.89533
ingestedAt: '2026-07-08T18:25:49.170Z'
---

## Overview

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

## Affected packages

- `swift < 2.3.1`
- `swift >= 2.4.0, < 2.5.1`

## Remediation

Upgrade to a patched release:

- `swift 2.3.1`
- `swift 2.5.1`
