keystonemiddleware vulnerabilities
CVEs whose affected-version data names the keystonemiddleware package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-22797Critical· 9.9An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication …
▾ MidnightOpenStack · keystonemiddlewareEPSS 0.66%via NVD
CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
▾ Twilightkeystone · keystoneEPSS 1.7%via OSV