CVE-2023-3637Medium· 6.5▾ SunlitDenial of service in neutron
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.0%
1.0% → 1.3%
Last analysed / modified upstream
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
neutron <= 22.0.2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
CVE-2015-3221MediumOpenStack Neutron Improper Input Validation vulnerability
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability