X-Copy-From Header Vulnerability in OpenStack Swift by OpenStack
CVE-2026-97149
5.3MEDIUM
What is CVE-2026-97149?
In OpenStack Swift versions prior to 2.38.2, the tempurl middleware fails to properly reject the X-Copy-From header in PUT requests. This oversight allows an attacker to exploit a signed PUT TempURL for an object, enabling them to specify an X-Copy-From header targeting any object within the same account. As a result, the copy middleware can deceptively transfer the targeted object, and the attacker can subsequently retrieve the victim's data using a GET TempURL for the newly created destination object. Notably, this issue does not permit cross-account copying.
Affected Version(s)
Swift 2.4.0 < 2.35.5
Swift 2.36.0 < 2.36.4
Swift 2.37.0 < 2.37.4
