keystone has 21 CVEs on record between 2013 and 2026. The busiest recent month was May 2026 with 4. The median CVSS is 6.8 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
Products
- keystone 21
Worst active — by depth score
CVE-2021-38155High· 7.5OpenStack Keystone allows information disclosure during account locking42CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation42CVE-2012-4456HighOpenStack Keystone Improper Authentication vulnerability42CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials42CVE-2025-65073High· 7.5OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.41
keystone vulnerabilities
CVEs affecting keystone, newest first. Open any entry for full detail, references, and exploit status.
21 CVEsRSS
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue
OpenStack Keystone has an Incorrect Authorization issue
CVE-2026-42998Medium· 6.0OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
CVE-2026-42999Medium· 6.0OpenStack Keystone has an Authorization Bypass
OpenStack Keystone has an Authorization Bypass
CVE-2025-65073High· 7.5OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
CVE-2021-38155High· 7.5OpenStack Keystone allows information disclosure during account locking
OpenStack Keystone allows information disclosure during account locking
CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone Allows Remote User Account Creation
CVE-2012-4413MediumOpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2013-4477LowOpenStack Identity Keystone Privilege Escalation vulnerability
OpenStack Identity Keystone Privilege Escalation vulnerability
CVE-2012-4457MediumOpenStack Keystone Token authorization for a user in a disabled tenant is allowed
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2012-4456HighOpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Improper Authentication vulnerability
CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
CVE-2015-3646MediumOpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
CVE-2014-0204MediumOpenStack Identity Keystone Improper Privilege Management
OpenStack Identity Keystone Improper Privilege Management
CVE-2014-3621MediumOpenStack Identity Keystone Exposure of Sensitive Information
OpenStack Identity Keystone Exposure of Sensitive Information
CVE-2013-2014MediumOpenStack Identity (Keystone) Denial of Service
OpenStack Identity (Keystone) Denial of Service
CVE-2014-3476MediumOpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
CVE-2013-0282MediumOpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
CVE-2013-0270Medium· 6.5OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
CVE-2017-2673High· 7.2An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…
CVE-2013-1865NoneOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.