---
id: CVE-2016-4428
aliases:
  - GHSA-grm6-x6mr-q3cv
  - PYSEC-2026-643
title: OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
summary: OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: horizon
product: horizon
ecosystem: pip
affected:
  - horizon < 8.0.2
  - 'horizon >= 9.0.0, < 9.1.0'
patched:
  - horizon 8.0.2
  - horizon 9.1.0
published: '2022-05-13'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-grm6-x6mr-q3cv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2016-4428'
  - url: >-
      https://github.com/openstack/horizon/commit/62b4e6f30a7ae7961805abdffdb3c7ae5c2b676a
  - url: >-
      https://github.com/openstack/horizon/commit/d585e5eb9acf92d10d39b6c2038917a7e8ac71bb
  - url: >-
      https://github.com/openstack/horizon/commit/fc8d70560401f3985e5672a4c580f10d51e985a4
  - url: 'https://access.redhat.com/errata/RHSA-2016:1268'
  - url: 'https://access.redhat.com/errata/RHSA-2016:1269'
  - url: 'https://access.redhat.com/errata/RHSA-2016:1270'
  - url: 'https://access.redhat.com/errata/RHSA-2016:1271'
  - url: 'https://access.redhat.com/errata/RHSA-2016:1272'
  - url: 'https://access.redhat.com/security/cve/CVE-2016-4428'
  - url: 'https://bugs.launchpad.net/horizon/+bug/1567673'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1343982'
  - url: 'https://review.openstack.org/329996'
  - url: 'https://review.openstack.org/329997'
  - url: 'https://review.openstack.org/329998'
  - url: 'https://security.openstack.org/ossa/OSSA-2016-010.html'
  - url: 'http://www.debian.org/security/2016/dsa-3617'
  - url: 'http://www.openwall.com/lists/oss-security/2016/06/17/4'
tags:
  - osv
  - pip
epss: 0.02085
epssPercentile: 0.80471
ingestedAt: '2026-07-08T18:25:49.772Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

## Affected packages

- `horizon < 8.0.2`
- `horizon >= 9.0.0, < 9.1.0`

## Remediation

Upgrade to a patched release:

- `horizon 8.0.2`
- `horizon 9.1.0`
