OpenStack Amphora Provider Driver Vulnerability in L7 Policy Fields
CVE-2026-94571

9.4CRITICAL

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94571?

In OpenStack Octavia prior to version 18.0.1, the Amphora provider driver allowed control characters to be introduced in the L7 policy fields, specifically redirect_url and redirect_prefix. While the RFC 3986 URL validator is designed to percent-encode such characters before validation, the lack of adequate checks meant that newlines could be passed without encoding. Consequently, this flaw enables an authenticated project member with access to a load balancer to inject arbitrary HAProxy directives via the REDIRECT_TO_URL policy, posing potential security risks to deployments utilizing this provider.

Affected Version(s)

Octavia 0.8.0 < 16.1.0

Octavia 17.0.0 < 17.0.1

Octavia 18.0.0 < 18.0.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.