CVE-2026-43002Medium· 5.3▾ SunlitAn issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
horizon >= 25.6.0, < 25.7.3Upgrade past the affected range:
horizon 25.7.3Affected packages:
horizon >= 25.6, < 25.7.3Patched in:
horizon 25.7.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55748Medium· 6.0OpenStack Horizon RC file generation does not escape special characters in project names
CVE-2014-3474LowOpenStack Horizon Cross-site scripting (XSS) vulnerability
CVE-2016-4428Medium· 5.4OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
CVE-2014-0157MediumOpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
CVE-2014-3473MediumHorizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
CVE-2014-3594LowOpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface