VulnSea

keystone has 21 CVEs on record between 2013 and 2026. The busiest recent month was May 2026 with 4. The median CVSS is 6.8 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.8
Publish → KEV
Last 90 days
0 prev 4

Products

  • keystone 21
21
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

keystone vulnerabilities

CVEs affecting keystone, newest first. Open any entry for full detail, references, and exploit status.

21 CVEsRSS

CVE-2026-44394Medium· 6.0
3mo ago

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

Sunlitkeystone · keystoneEPSS 0.25%via OSV
CVE-2026-43000Medium· 6.0
3mo ago

OpenStack Keystone has an Incorrect Authorization issue

OpenStack Keystone has an Incorrect Authorization issue

Sunlitkeystone · keystoneEPSS 0.33%via OSV
CVE-2026-42998Medium· 6.0
3mo ago

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

Sunlitkeystone · keystoneEPSS 0.30%via OSV
CVE-2026-42999Medium· 6.0
3mo ago

OpenStack Keystone has an Authorization Bypass

OpenStack Keystone has an Authorization Bypass

Sunlitkeystone · keystoneEPSS 0.33%via OSV
CVE-2025-65073High· 7.5
10mo ago

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

Twilightkeystone · keystoneEPSS 0.23%via OSV
CVE-2021-38155High· 7.5
4y ago

OpenStack Keystone allows information disclosure during account locking

OpenStack Keystone allows information disclosure during account locking

Twilightkeystone · keystoneEPSS 2.5%via OSV
CVE-2012-3542High· 7.5
4y ago

OpenStack Keystone Allows Remote User Account Creation

OpenStack Keystone Allows Remote User Account Creation

Twilightkeystone · keystoneEPSS 2.5%via OSV
CVE-2012-4413Medium
4y ago

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

Sunlitkeystone · keystoneEPSS 1.9%via OSV
CVE-2013-4477Low
4y ago

OpenStack Identity Keystone Privilege Escalation vulnerability

OpenStack Identity Keystone Privilege Escalation vulnerability

Sunlitkeystone · keystoneEPSS 0.45%via OSV
CVE-2012-4457Medium
4y ago

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

Sunlitkeystone · keystoneEPSS 2.3%via OSV
CVE-2012-4456High
4y ago

OpenStack Keystone Improper Authentication vulnerability

OpenStack Keystone Improper Authentication vulnerability

Twilightkeystone · keystoneEPSS 4.0%via OSV
CVE-2015-7546High· 7.5
4y ago

OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials

OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials

Twilightkeystone · keystoneEPSS 1.7%via OSV
CVE-2015-3646Medium
4y ago

OpenStack Keystone Logs Passwords

OpenStack Keystone Logs Passwords

Sunlitkeystone · keystoneEPSS 2.9%via OSV
CVE-2014-0204Medium
4y ago

OpenStack Identity Keystone Improper Privilege Management

OpenStack Identity Keystone Improper Privilege Management

Sunlitkeystone · keystoneEPSS 1.4%via OSV
CVE-2014-3621Medium
4y ago

OpenStack Identity Keystone Exposure of Sensitive Information

OpenStack Identity Keystone Exposure of Sensitive Information

Sunlitkeystone · keystoneEPSS 2.1%via OSV
CVE-2013-2014Medium
4y ago

OpenStack Identity (Keystone) Denial of Service

OpenStack Identity (Keystone) Denial of Service

Sunlitkeystone · keystoneEPSS 3.3%via OSV
CVE-2014-3476Medium
4y ago

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

Sunlitkeystone · keystoneEPSS 2.3%via OSV
CVE-2013-0282Medium
4y ago

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

Sunlitkeystone · keystoneEPSS 1.8%via OSV
CVE-2013-0270Medium· 6.5
4y ago

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

Sunlitkeystone · keystoneEPSS 3.2%via OSV
CVE-2017-2673High· 7.2
8y ago

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…

Twilightkeystone · keystoneEPSS 1.9%via OSV
CVE-2013-1865None
13y ago

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

Sunlitkeystone · keystoneEPSS 2.6%via OSV
keystone vulnerabilities (CVEs) · VulnSea