Vulnerability in OpenStack Amphora Provider Driver Affects Load Balancer Configuration
CVE-2026-94572
9.4CRITICAL
What is CVE-2026-94572?
In OpenStack Octavia prior to version 18.0.1, a vulnerability exists in the Amphora provider driver that fails to properly validate the TLS ciphers input for control characters. This oversight allows an authenticated user with access to a TLS-enabled load balancer to inject newline characters into the HAProxy configuration. Consequently, this can lead to the execution of arbitrary HAProxy directives, potentially compromising the load balancer's operational integrity and security. Only instances utilizing the Amphora provider driver are susceptible to this exploitation.
Affected Version(s)
Octavia 6.0.0 < 16.1.0
Octavia 17.0.0 < 17.0.1
Octavia 18.0.0 < 18.0.1
