Server-Side Request Forgery Risk in OpenStack Swift S3API Middleware
CVE-2026-71192

6MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71192?

In OpenStack Swift versions up to 2.38.0, an insufficient sanitization of Swift-native control headers in the S3API middleware poses a serious risk. When configured with s3_acl=true, it allows attackers to inject headers into signed PUT requests. This exploitation enables an attacker to initiate unauthorized server-side copy operations from another tenant's private object, effectively bypassing the required source object permissions. As a result, malicious users can access sensitive data without necessary authorization, provided they know the specific project_id, container name, and object name, posing significant privacy and data integrity concerns.

Affected Version(s)

Swift 2.18.0 < 2.35.4

Swift 2.36.0 < 2.36.3

Swift 2.37.0 < 2.37.3

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.