CVE-2026-46448Medium· 5.4▾ SunlitOpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
Erichen from the Institute of Computing Technology, Chinese Academy of Sciences reported that Nova's server create API does not strip internal scheduler hints. An authenticated user can bypass Placement resource claims and scheduling constraint enforcement, including availability zone, host aggregate, and image trait restrictions. The resulting instance has no Placement allocation, which can lead to compute node resource exhaustion and cross-tenant data persistence on NVMe devices after instance deletion. Deployments running Nova 18.0.0 or later are affected.
nova >= 18.0.0, <= 31.3.0nova >= 32.0.0, < 32.2.1nova >= 33.0.0, < 33.0.2Upgrade to a patched release:
nova 32.2.1nova 33.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2017-16239Medium· 6.5OpenStack Nova Filter Scheduler Bypass
CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2011-4596MediumOpenStack Nova Multiple directory traversal vulnerabilities
CVE-2012-1585MediumOpenStack Nova Long server names grow nova-api log files significantly