VulnSea

keystone vulnerabilities

CVEs whose affected-version data names the keystone package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

24 CVEsRSS

CVE-2026-90460High· 7.6PoC
1w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

MidnightOpenStack · KeystoneEPSS 0.34%via NVD
CVE-2026-80183High· 7.1
3w ago

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

TwilightOpenStack · KeystoneEPSS 0.23%via NVD
CVE-2026-44394Medium· 6.0
3mo ago

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

Sunlitkeystone · keystoneEPSS 0.25%via OSV
CVE-2026-43000Medium· 6.0
3mo ago

OpenStack Keystone has an Incorrect Authorization issue

OpenStack Keystone has an Incorrect Authorization issue

Sunlitkeystone · keystoneEPSS 0.33%via OSV
CVE-2026-42998Medium· 6.0
3mo ago

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

Sunlitkeystone · keystoneEPSS 0.30%via OSV
CVE-2026-42999Medium· 6.0
3mo ago

OpenStack Keystone has an Authorization Bypass

OpenStack Keystone has an Authorization Bypass

Sunlitkeystone · keystoneEPSS 0.33%via OSV
CVE-2025-65073High· 7.5
10mo ago

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

Twilightkeystone · keystoneEPSS 0.23%via OSV
CVE-2021-38155High· 7.5
4y ago

OpenStack Keystone allows information disclosure during account locking

OpenStack Keystone allows information disclosure during account locking

Twilightkeystone · keystoneEPSS 2.5%via OSV
CVE-2012-3542High· 7.5
4y ago

OpenStack Keystone Allows Remote User Account Creation

OpenStack Keystone Allows Remote User Account Creation

Twilightkeystone · keystoneEPSS 2.5%via OSV
CVE-2012-4413Medium
4y ago

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

Sunlitkeystone · keystoneEPSS 1.9%via OSV
CVE-2013-4477Low
4y ago

OpenStack Identity Keystone Privilege Escalation vulnerability

OpenStack Identity Keystone Privilege Escalation vulnerability

Sunlitkeystone · keystoneEPSS 0.45%via OSV
CVE-2012-4457Medium
4y ago

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

Sunlitkeystone · keystoneEPSS 2.3%via OSV
CVE-2012-4456High
4y ago

OpenStack Keystone Improper Authentication vulnerability

OpenStack Keystone Improper Authentication vulnerability

Twilightkeystone · keystoneEPSS 4.0%via OSV
CVE-2015-7546High· 7.5
4y ago

OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials

OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials

Twilightkeystone · keystoneEPSS 1.7%via OSV
CVE-2015-3646Medium
4y ago

OpenStack Keystone Logs Passwords

OpenStack Keystone Logs Passwords

Sunlitkeystone · keystoneEPSS 2.9%via OSV
CVE-2014-0204Medium
4y ago

OpenStack Identity Keystone Improper Privilege Management

OpenStack Identity Keystone Improper Privilege Management

Sunlitkeystone · keystoneEPSS 1.4%via OSV
CVE-2014-3621Medium
4y ago

OpenStack Identity Keystone Exposure of Sensitive Information

OpenStack Identity Keystone Exposure of Sensitive Information

Sunlitkeystone · keystoneEPSS 2.1%via OSV
CVE-2013-2014Medium
4y ago

OpenStack Identity (Keystone) Denial of Service

OpenStack Identity (Keystone) Denial of Service

Sunlitkeystone · keystoneEPSS 3.3%via OSV
CVE-2014-3476Medium
4y ago

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

Sunlitkeystone · keystoneEPSS 2.3%via OSV
CVE-2013-2255Medium· 5.9
4y ago

OpenStack Keystone and other components vulnerable to Improper Certificate Validation

OpenStack Keystone and other components vulnerable to Improper Certificate Validation

Sunlitpython-keystoneclient · python-keystoneclientEPSS 0.97%via OSV
CVE-2013-0282Medium
4y ago

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

Sunlitkeystone · keystoneEPSS 1.8%via OSV
CVE-2013-0270Medium· 6.5
4y ago

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

Sunlitkeystone · keystoneEPSS 3.2%via OSV
CVE-2017-2673High· 7.2
8y ago

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…

Twilightkeystone · keystoneEPSS 1.9%via OSV
CVE-2013-1865None
13y ago

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

Sunlitkeystone · keystoneEPSS 2.6%via OSV
keystone vulnerabilities (CVEs) · VulnSea