neutron has 11 CVEs on record between 2022 and 2026. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- neutron 11
Worst active — by depth score
CVE-2016-5363High· 8.2OpenStack Neutron Intended MAC-spoofing protection mechanism bypass46CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism46CVE-2015-3221MediumOpenStack Neutron Improper Input Validation vulnerability42CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement41CVE-2023-3637Medium· 6.5Denial of service in neutron36
neutron vulnerabilities
CVEs affecting neutron, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
OpenStack Neutron has an Incorrect Authorization issue
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2023-3637Medium· 6.5Denial of service in neutron
Denial of service in neutron
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
CVE-2015-5240LowOpenStack Neutron Race condition vulnerability
OpenStack Neutron Race condition vulnerability
CVE-2016-5363High· 8.2OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
OpenStack Neutron Intended MAC-spoofing protection mechanism bypass
CVE-2014-0056MediumOpenStack Neutron Improper Authentication vulnerability
OpenStack Neutron Improper Authentication vulnerability
CVE-2015-3221MediumPoCOpenStack Neutron Improper Input Validation vulnerability
OpenStack Neutron Improper Input Validation vulnerability
CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability
OpenStack Neutron Race Condition vulnerability