OpenStack Amphora Provider Driver Vulnerability in L7 Policy Fields
CVE-2026-94571
9.4CRITICAL
What is CVE-2026-94571?
In OpenStack Octavia prior to version 18.0.1, the Amphora provider driver allowed control characters to be introduced in the L7 policy fields, specifically redirect_url and redirect_prefix. While the RFC 3986 URL validator is designed to percent-encode such characters before validation, the lack of adequate checks meant that newlines could be passed without encoding. Consequently, this flaw enables an authenticated project member with access to a load balancer to inject arbitrary HAProxy directives via the REDIRECT_TO_URL policy, posing potential security risks to deployments utilizing this provider.
Affected Version(s)
Octavia 0.8.0 < 16.1.0
Octavia 17.0.0 < 17.0.1
Octavia 18.0.0 < 18.0.1
