openstack_services_on_openshift vulnerabilities
CVEs whose affected-version data names the openstack_services_on_openshift package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-43001High· 8.0OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…
A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…
▾ TwilightRed Hat · Red Hat OpenStack Platform 17.1EPSS 0.47%via CSAF
CVE-2026-40683High· 7.7OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)
A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…
▾ TwilightRed Hat · Red Hat OpenStack Platform 13 (Queens)EPSS 0.34%via CSAF