ReDoS Vulnerability in OpenStack Swift Proxy Server
CVE-2026-71190

8.7HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71190?

In OpenStack Swift versions prior to 2.38.0, there exists a vulnerability in the proxy server's Accept header parser that is susceptible to catastrophic backtracking. An unauthenticated attacker can exploit this weakness by sending a specially crafted Accept header, which can lead to significant CPU resource consumption due to exponential processing time. For instance, a payload containing multiple backslash-character pairs can result in over 30 seconds of CPU time being consumed, potentially exhausting all proxy worker threads. This condition ultimately leads to a denial of service, impacting the availability of the Swift service.

Affected Version(s)

Swift 1.9.1 < 2.35.4

Swift 2.36.0 < 2.36.3

Swift 2.37.0 < 2.37.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.