ReDoS Vulnerability in OpenStack Swift Proxy Server
CVE-2026-71190
8.7HIGH
What is CVE-2026-71190?
In OpenStack Swift versions prior to 2.38.0, there exists a vulnerability in the proxy server's Accept header parser that is susceptible to catastrophic backtracking. An unauthenticated attacker can exploit this weakness by sending a specially crafted Accept header, which can lead to significant CPU resource consumption due to exponential processing time. For instance, a payload containing multiple backslash-character pairs can result in over 30 seconds of CPU time being consumed, potentially exhausting all proxy worker threads. This condition ultimately leads to a denial of service, impacting the availability of the Swift service.
Affected Version(s)
Swift 1.9.1 < 2.35.4
Swift 2.36.0 < 2.36.3
Swift 2.37.0 < 2.37.3
