Nova vulnerabilities
CVEs whose affected-version data names the Nova package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
38 CVEsRSS
CVE-2026-46448Medium· 5.4OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
CVE-2026-24708High· 8.2An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend t…
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2015-9543Low· 3.3OpenStack Nova can leak consoleauth token into log files
OpenStack Nova can leak consoleauth token into log files
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2013-2096MediumOpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2013-4463LowOpenStack Nova denial of service through compressed disk images
OpenStack Nova denial of service through compressed disk images
CVE-2013-4278LowOpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
CVE-2013-4469LowOpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
CVE-2013-4497MediumOpenStack Compute Nova Improper Access Control
OpenStack Compute Nova Improper Access Control
CVE-2013-6419MediumOpenStack Nova Router metadata queries are not restricted by tenant
OpenStack Nova Router metadata queries are not restricted by tenant
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259MediumOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2011-4596MediumOpenStack Nova Multiple directory traversal vulnerabilities
OpenStack Nova Multiple directory traversal vulnerabilities
CVE-2012-1585MediumOpenStack Nova Long server names grow nova-api log files significantly
OpenStack Nova Long server names grow nova-api log files significantly
CVE-2013-4185MediumOpenStack Nova Denial of Service in network source security groups
OpenStack Nova Denial of Service in network source security groups
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-6437MediumOpenStack Nova DoS through ephemeral disk backing files
OpenStack Nova DoS through ephemeral disk backing files
CVE-2013-7048LowOpenStack Nova live snapshots use an insecure local directory
OpenStack Nova live snapshots use an insecure local directory
CVE-2014-8333MediumOpenStack Nova VMware instance leak potentially leading to compute DoS
OpenStack Nova VMware instance leak potentially leading to compute DoS
CVE-2015-5162High· 7.5OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
CVE-2015-8749Medium· 5.9OpenStack Nova Potential Xen connection password leak via StorageError
OpenStack Nova Potential Xen connection password leak via StorageError
CVE-2014-3608MediumOpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
CVE-2015-7713MediumOpenStack Compute (Nova) allows remote attackers to bypass intended restriction
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
CVE-2013-2256MediumOpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
CVE-2016-2140Medium· 5.3OpenStack Nova host data access through resize/migration
OpenStack Nova host data access through resize/migration