---
id: CVE-2017-8761
aliases:
  - GHSA-8fxc-qm65-vpxg
  - PYSEC-2026-751
title: Temporary urls leaked via logging
summary: Temporary urls leaked via logging
severity: low
vendor: swift
product: swift
ecosystem: pip
affected:
  - swift < 2.15.2
patched:
  - swift 2.15.2
published: '2021-06-08'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-8fxc-qm65-vpxg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2017-8761'
  - url: 'https://bugs.launchpad.net/swift/+bug/1685798/comments/18'
  - url: 'https://launchpad.net/bugs/1685798'
tags:
  - osv
  - pip
epss: 0.00795
epssPercentile: 0.5446
ingestedAt: '2026-07-08T18:25:47.475Z'
---

## Overview

In OpenStack Swift prior to 2.15.2, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

## Affected packages

- `swift < 2.15.2`

## Remediation

Upgrade to a patched release:

- `swift 2.15.2`
