---
id: CVE-2022-23452
aliases:
  - GHSA-6p2h-rjj7-2j63
  - PYSEC-2026-785
title: openstack-barbican Denial of Service vulnerability
summary: openstack-barbican Denial of Service vulnerability
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'
vendor: barbican
product: barbican
ecosystem: pip
affected:
  - barbican < 14.0.0
patched:
  - barbican 14.0.0
published: '2022-09-02'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6p2h-rjj7-2j63'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23452'
  - url: >-
      https://github.com/openstack/barbican/commit/6c841b23afa8ed6fa4cd01ba1a6bebfb60f06ae5
  - url: 'https://access.redhat.com/errata/RHSA-2022:5114'
  - url: 'https://access.redhat.com/errata/RHSA-2022:8874'
  - url: 'https://access.redhat.com/security/cve/CVE-2022-23452'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2022908'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025090'
  - url: 'https://review.opendev.org/c/openstack/barbican/+/814200'
  - url: 'https://storyboard.openstack.org/#!/story/2009297'
  - url: 'https://storyboard.openstack.org/#%21/story/2009297'
tags:
  - osv
  - pip
epss: 0.01266
epssPercentile: 0.68464
ingestedAt: '2026-07-08T18:25:46.494Z'
---

## Overview

An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

## Affected packages

- `barbican < 14.0.0`

## Remediation

Upgrade to a patched release:

- `barbican 14.0.0`
