rhosp-rhel8/openstack-nova-api vulnerabilities
CVEs whose affected-version data names the rhosp-rhel8/openstack-nova-api package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92091Medium· 5.9PoCA flaw was found in jwcrypto
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacke…
▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.50%via NVD
CVE-2026-80179Medium· 5.9PoCJwcrypto: jwcrypto: denial of service via malformed jwe tokens
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memor…
▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.25%via CVEORG