WSGI Transport Vulnerability in OpenStack Zaqar Affects Multiple Deployments
CVE-2026-97404
What is CVE-2026-97404?
In OpenStack Zaqar prior to version 22.0.2, the WSGI transport improperly handles the URL-Signature header. An unauthenticated remote attacker who knows the UUID of a target project can exploit this by sending requests with an empty URL-Signature header. This allows the attacker to bypass Keystone authentication and pre-signed URL verification mechanisms. Consequently, this vulnerability enables the attacker to read, enumerate, create, and delete a project's queues, messages, claims, and subscriptions. Additionally, if the attacker successfully claims an administrative role, they can execute administrative operations, such as managing pools and flavors, in deployments utilizing admin_mode. It is important to note that this issue affects only deployments that use the WSGI transport with a configured authentication strategy; deployments relying on the websocket transport remain unaffected.
Affected Version(s)
Zaqar 1.0.0 < 20.1.2
Zaqar 21.0.0 < 21.0.2
Zaqar 22.0.0 < 22.0.2
