nova has 34 CVEs on record between 2022 and 2026. The median CVSS is 5.9 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Weakness classes
Products
- nova 34
Worst active — by depth score
CVE-2021-3654Medium· 6.1Open Redirect in CPython that affects users of OpenStack Nova51CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times48CVE-2017-18191High· 7.5OpenStack Nova Denial of service attack on the compute host42CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data 36CVE-2017-16239Medium· 6.5OpenStack Nova Filter Scheduler Bypass36
nova vulnerabilities
CVEs affecting nova, newest first. Open any entry for full detail, references, and exploit status.
34 CVEsRSS
CVE-2026-46448Medium· 5.4OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2015-9543Low· 3.3OpenStack Nova can leak consoleauth token into log files
OpenStack Nova can leak consoleauth token into log files
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2013-2096MediumOpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2013-4463LowOpenStack Nova denial of service through compressed disk images
OpenStack Nova denial of service through compressed disk images
CVE-2013-4278LowOpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
CVE-2013-4469LowOpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
CVE-2013-4497MediumOpenStack Compute Nova Improper Access Control
OpenStack Compute Nova Improper Access Control
CVE-2013-6419MediumOpenStack Nova Router metadata queries are not restricted by tenant
OpenStack Nova Router metadata queries are not restricted by tenant
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259MediumOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2011-4596MediumOpenStack Nova Multiple directory traversal vulnerabilities
OpenStack Nova Multiple directory traversal vulnerabilities
CVE-2012-1585MediumOpenStack Nova Long server names grow nova-api log files significantly
OpenStack Nova Long server names grow nova-api log files significantly
CVE-2013-4185MediumOpenStack Nova Denial of Service in network source security groups
OpenStack Nova Denial of Service in network source security groups
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service
OpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-6437MediumOpenStack Nova DoS through ephemeral disk backing files
OpenStack Nova DoS through ephemeral disk backing files
CVE-2013-7048LowOpenStack Nova live snapshots use an insecure local directory
OpenStack Nova live snapshots use an insecure local directory
CVE-2014-8333MediumOpenStack Nova VMware instance leak potentially leading to compute DoS
OpenStack Nova VMware instance leak potentially leading to compute DoS
CVE-2015-8749Medium· 5.9OpenStack Nova Potential Xen connection password leak via StorageError
OpenStack Nova Potential Xen connection password leak via StorageError
CVE-2014-3608MediumOpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
CVE-2015-7713MediumOpenStack Compute (Nova) allows remote attackers to bypass intended restriction
OpenStack Compute (Nova) allows remote attackers to bypass intended restriction
CVE-2013-2256MediumOpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
CVE-2016-2140Medium· 5.3OpenStack Nova host data access through resize/migration
OpenStack Nova host data access through resize/migration
CVE-2014-3708MediumOpenStack Compute (Nova) Denial of Service vulnerability
OpenStack Compute (Nova) Denial of Service vulnerability
CVE-2015-3241MediumOpenStack Nova instance migration process does not stop when instance is deleted
OpenStack Nova instance migration process does not stop when instance is deleted
CVE-2017-16239Medium· 6.5OpenStack Nova Filter Scheduler Bypass
OpenStack Nova Filter Scheduler Bypass
CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times