VulnSea

openstack has 15 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 3 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 7.6 (high), with 3 rated critical. None have a confirmed exploitation report. Most affected products: Blazar (2), Glance (2), Ironic (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.6
Publish → KEV
Last 90 days
8 prev 3

Products

  • Blazar 2
  • Glance 2
  • Ironic 2
  • Keystone 2
  • Octavia 2
  • Nova 1
15
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

OpenStack vulnerabilities

CVEs affecting OpenStack, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-94572Critical· 9.4
today

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and t…

MidnightOpenStack · Octaviavia CVEORG
CVE-2026-94571Critical· 9.4
today

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, …

MidnightOpenStack · Octaviavia CVEORG
CVE-2026-93854High· 7.2
3d ago

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id})

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to …

TwilightOpenStack · BlazarEPSS 0.24%via NVD
CVE-2026-93852High· 7.1
3d ago

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST …

TwilightOpenStack · BlazarEPSS 0.22%via NVD
CVE-2026-71198High· 7.0
1w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2026-90460High· 7.6PoC
1w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

MidnightOpenStack · KeystoneEPSS 0.34%via NVD
CVE-2026-90461Medium· 6.3
1w ago

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

SunlitOpenStack · IronicEPSS 0.21%via NVD
CVE-2026-80183High· 7.1
3w ago

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

TwilightOpenStack · KeystoneEPSS 0.23%via NVD
CVE-2026-43002Medium· 5.3
4mo ago

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…

Sunlitopenstack · horizonEPSS 0.36%via NVD
CVE-2026-42997High· 7.7
4mo ago

An issue was discovered in idrac in OpenStack Ironic before 35.0.1

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…

Twilightopenstack · ironicEPSS 0.43%via NVD
CVE-2026-43003High· 8.0
4mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

Twilightopenstack · ironic_python_agentEPSS 0.98%via NVD
CVE-2026-24708High· 8.2
7mo ago

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend t…

TwilightOpenStack · NovaEPSS 0.38%via NVD
CVE-2026-22797Critical· 9.9
8mo ago

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication …

MidnightOpenStack · keystonemiddlewareEPSS 0.66%via NVD
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

Sunlitopenstack · glanceEPSS 2.1%via NVD
CVE-2013-0335High· 7.6
13y ago

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Twilightopenstack · essexEPSS 2.1%via NVD
OpenStack vulnerabilities (CVEs) · VulnSea