---
id: CVE-2026-43002
title: An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3
summary: >-
  An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3.
  There is a write operation to the session storage backend before
  authentication and thus storage can be exhausted by unauthenticated requests.
  This is a regression…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-696
vendor: openstack
product: horizon
affected:
  - 'horizon >= 25.6.0, < 25.7.3'
patched:
  - horizon 25.7.3
published: '2026-05-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:22:48.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43002'
references:
  - url: 'https://bugs.launchpad.net/horizon/+bug/2150331'
    label: cve@mitre.org
  - url: 'https://security.openstack.org/ossa/OSSA-2026-009.html'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/05/05/7'
    label: cve@mitre.org
  - url: 'https://bugs.launchpad.net/horizon/+bug/2150331'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43002'
  - url: 'https://github.com/openstack/horizon'
tags:
  - nvd
  - osv
  - pip
epss: 0.00597
epssPercentile: 0.46221
aliases:
  - GHSA-vxvf-xvm3-p8j5
  - PYSEC-2026-2520
ecosystem: pip
ingestedAt: '2026-07-13T18:58:03.939Z'
---

## Overview

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

## Affected

- `horizon >= 25.6.0, < 25.7.3`

## Remediation

Upgrade past the affected range:

- `horizon 25.7.3`

## Package advisory (CVE-2026-43002)

Affected packages:

- `horizon >= 25.6, < 25.7.3`

Patched in:

- `horizon 25.7.3`

Source: https://osv.dev/vulnerability/GHSA-vxvf-xvm3-p8j5
