swift has 12 CVEs on record between 2014 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- swift 12
Worst active — by depth score
CVE-2016-0738High· 7.5OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service42CVE-2016-0737High· 7.5OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service42CVE-2013-2161HighOpenStack Swift Unchecked user input in XML responses42CVE-2026-49017HighOpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body41CVE-2022-47950Medium· 6.5OpenStack Swift XML external entities (XXE) Injection36
swift vulnerabilities
CVEs affecting swift, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-49017HighOpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
CVE-2022-47950Medium· 6.5OpenStack Swift XML external entities (XXE) Injection
OpenStack Swift XML external entities (XXE) Injection
CVE-2013-4155MediumOpenStack Swift allows authenticated users to cause a denial of service
OpenStack Swift allows authenticated users to cause a denial of service
CVE-2014-7960MediumOpenStack Swift metadata constraints are not correctly enforced
OpenStack Swift metadata constraints are not correctly enforced
CVE-2016-0738High· 7.5OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
CVE-2016-0737High· 7.5OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
OpenStack Object Storage (Swift) allows remote attackers to cause a denial of service
CVE-2014-3497MediumOpenStack Swift Cross-site Scriping vulnerability
OpenStack Swift Cross-site Scriping vulnerability
CVE-2015-5223MediumOpenStack Object Storage (Swift) Sensitive Data Exposure
OpenStack Object Storage (Swift) Sensitive Data Exposure
CVE-2015-1856MediumOpenStack Swift Unauthorized delete of versioned Swift object
OpenStack Swift Unauthorized delete of versioned Swift object
CVE-2013-2161HighOpenStack Swift Unchecked user input in XML responses
OpenStack Swift Unchecked user input in XML responses
CVE-2017-8761LowTemporary urls leaked via logging
Temporary urls leaked via logging
CVE-2014-0006NoneThe TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.