openstack-cyborg vulnerabilities
CVEs whose affected-version data names the openstack-cyborg package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-40214Medium· 6.3OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
▾ Sunlitopenstack-cyborg · openstack-cyborgEPSS 0.21%via OSV
CVE-2026-40213High· 7.4OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
▾ Twilightopenstack-cyborg · openstack-cyborgEPSS 0.21%via OSV