---
id: CVE-2026-44394
aliases:
  - GHSA-whqr-fgm5-x77q
  - PYSEC-2026-603
title: >-
  OpenStack Keystone's federated token rescoping mechanism doesn't propagate the
  original token's expiry to the newly issued token
summary: >-
  OpenStack Keystone's federated token rescoping mechanism doesn't propagate the
  original token's expiry to the newly issued token
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - 'keystone >= 14.0.0, < 27.0.2'
  - 'keystone >= 28.0.0, < 28.0.2'
  - 'keystone >= 29.0.0, < 29.0.2'
patched:
  - keystone 27.0.2
  - keystone 28.0.2
  - keystone 29.0.2
published: '2026-05-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:47.930367522Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-whqr-fgm5-x77q'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44394'
  - url: 'https://bugs.launchpad.net/keystone/+bug/2150379'
  - url: 'https://github.com/openstack/keystone'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2026-603.yaml
  - url: 'https://security.openstack.org/ossa/OSSA-2026-015.html'
tags:
  - osv
  - pip
epss: 0.00321
epssPercentile: 0.22478
ingestedAt: '2026-07-08T18:25:53.795Z'
---

## Overview

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.

## Affected packages

- `keystone >= 14.0.0, < 27.0.2`
- `keystone >= 28.0.0, < 28.0.2`
- `keystone >= 29.0.0, < 29.0.2`

## Remediation

Upgrade to a patched release:

- `keystone 27.0.2`
- `keystone 28.0.2`
- `keystone 29.0.2`
